Compare commits

...
860 Commits
Author SHA1 Message Date
Evan Hunt 304fe688c0 prepare release of 9.7.3-P3 2011-06-21 20:36:58 +00:00
Automatic Updater df25aafb5c update 2011-06-21 20:16:33 +00:00
Evan Hunt f619d8eb7d 3124. [bug] Use an rdataset attribute flag to indicate
negative-cache records rather than using rrtype 0;
			this will prevent problems when that rrtype is
			used in actual DNS packets.  [RT #24777]
2011-06-21 20:14:48 +00:00
Automatic Updater c7a42a020c update 2011-06-09 04:18:09 +00:00
Evan Hunt 200a19bc50 forgot to bump libdns API revision number for 9.7.3-P2 2011-06-09 04:11:39 +00:00
Automatic Updater 3b5894744c update 2011-06-09 00:17:00 +00:00
Automatic Updater 1c51d84077 update copyright notice 2011-06-08 23:46:55 +00:00
Automatic Updater e00638087f newcopyrights 2011-06-08 23:30:28 +00:00
Automatic Updater 63b6432621 update 2011-06-08 22:16:20 +00:00
Evan Hunt f6d19bf03c patch security flaw [rt24777], and prepare release of 9.7.3-P2 2011-06-08 22:07:11 +00:00
Automatic Updater 11cee249f6 update 2011-06-07 00:16:45 +00:00
Automatic Updater 9c0805dbc1 update copyright notice 2011-06-06 23:46:32 +00:00
Automatic Updater efcf3c9fef update 2011-06-06 02:17:15 +00:00
Automatic Updater 0a701fe8a5 cleanup removed files 2011-06-06 01:23:00 +00:00
Automatic Updater f578ef48eb update 2011-06-06 00:16:57 +00:00
Automatic Updater 0358fb27c4 update 2011-06-05 23:55:01 +00:00
Automatic Updater a60d8f3c3c update 2011-06-03 00:17:13 +00:00
Automatic Updater 038f59e92c regen 2011-06-02 23:30:33 +00:00
Automatic Updater 469e51a063 update 2011-05-27 04:52:27 +00:00
Evan Hunt 3f30124cd6 add dns_trust_totext to def file 2011-05-27 00:58:50 +00:00
Evan Hunt e054439223 rolling 9.7.3-P1
3121.   [security]      An authoritative name server sending a negative
                        response containing a very large RRset could
                        trigger an off-by-one error in the ncache code
                        and crash named. [RT #24650]

3120.	[bug]		Named could fail to validate zones listed in a DLV
			that validated insecure without using DLV and had
			DS records in the parent zone. [RT #24631]
2011-05-27 00:43:06 +00:00
cvs2git 9fd7748f0f This commit was manufactured by cvs2git to create branch 'v9_7_3_patch'. 2011-02-26 02:26:41 +00:00
cvs2git eefb0cb790 This commit was manufactured by cvs2git to create branch
'ATT2_9_7_3_w_rt22852'.
2011-02-26 02:26:35 +00:00
cvs2git c6cf59fb0b This commit was manufactured by cvs2git to create branch
'custom_NOMINET_v9_7'.
2011-02-26 02:26:34 +00:00
Evan Hunt ef421f66f4 3043. [test] Merged in the NetBSD ATF test framework (currently
version 0.12) for development of future unit tests.
                        Use configure --with-atf to build ATF internally
                        or configure --with-atf=prefix to use an external
                        copy.  [RT #23209]
2011-02-26 02:26:33 +00:00
Automatic Updater 9eecb34b66 auto update 2011-02-25 23:16:12 +00:00
Evan Hunt 7cc5632595 3042. [bug] dig +trace could fail attempting to use IPv6
addresses on systems with only IPv4 connectivity.
			[RT #23797]
2011-02-25 23:11:13 +00:00
Automatic Updater d31e7b32ee auto update 2011-02-24 23:16:07 +00:00
Mark Andrews 2f09e7c3fc 3041. [bug] dnssec-signzone failed to generate new signatures on
ttl changes. [RT #23330]
2011-02-24 03:04:43 +00:00
Automatic Updater 8a8d38eb8e regen HEAD 2011-02-24 01:14:22 +00:00
Automatic Updater 45caada8cb update copyright notice 2011-02-23 23:47:20 +00:00
Automatic Updater 738c40ff67 auto update 2011-02-23 23:16:00 +00:00
Mark Andrews 4f07b2b00c 3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
                        top of the zone. [RT #23338]
2011-02-23 11:30:35 +00:00
Mark Andrews ddd40390be changes # 2011-02-23 03:10:26 +00:00
Mark Andrews 0e507dbb81 2039. [func] Redirect on NXDOMAIN support. [RT #23146] 2011-02-23 03:08:11 +00:00
Scott Mann 3b46648b02 Revert the previous commit...made on wrong branch. 2011-02-22 22:57:23 +00:00
Scott Mann 44b49a34b1 Added some comments. 2011-02-22 22:50:45 +00:00
Mark Andrews fd5d7b4b1c 2038. [bug] Install <dns/rpz.h>. [RT #23342] 2011-02-22 11:48:02 +00:00
Automatic Updater 5b17a70a35 update 2011-02-22 07:15:59 +00:00
Mark Andrews 5715e1c6f6 2037. [doc] Update COPYRIGHT to contain all the individual
copyright notices that cover various parts.
2011-02-22 06:29:42 +00:00
Automatic Updater 01e75ee673 update 2011-02-22 04:16:48 +00:00
Mark Andrews b795de862b 2036. [bug] Check built-in zone arguments to see if the zone
is re-usable or not. [RT #21914]
2011-02-22 04:14:30 +00:00
Automatic Updater be74b463a2 update 2011-02-22 00:16:37 +00:00
Automatic Updater b01d422daf update copyright notice 2011-02-21 23:47:45 +00:00
Mark Andrews 4b45a8fc5a handle cname response 2011-02-21 23:37:31 +00:00
Automatic Updater 930f6069e5 newcopyrights 2011-02-21 23:30:44 +00:00
Automatic Updater 7a268f7584 auto update 2011-02-21 23:16:14 +00:00
Automatic Updater 1f4a8b7232 update 2011-02-21 08:15:54 +00:00
Mark Andrews c12904ec53 3035. [cleanup] Simplify by using strlcpy. [RT #22521] 2011-02-21 07:34:57 +00:00
Mark Andrews 0a92db42c6 3034. [cleanup] nslookup: use strlcpy instead of safecopy. [RT #22521] 2011-02-21 07:22:21 +00:00
Automatic Updater b062d1ba6d update 2011-02-21 07:15:51 +00:00
Mark Andrews a360461b34 check for snprintf failure 2011-02-21 07:14:43 +00:00
Mark Andrews 17c98e7add 3033. [cleanup] Add two INSIST(bucket != DNS_ADB_INVALIDBUCKET).
[RT #22521]
2011-02-21 07:08:33 +00:00
Mark Andrews 699e00089f 3032. [bug] rdatalist.c: add missing REQUIREs. [RT #22521] 2011-02-21 07:01:09 +00:00
Mark Andrews 6883a918f7 3031. [bug] dns_rdataclass_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:50:42 +00:00
Mark Andrews e01f55daa4 3030. [bug] dns_rdatatype_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:41:07 +00:00
Mark Andrews 4c577cbd1e 3029. [bug] isc_netaddr_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:30:06 +00:00
Mark Andrews 2ba2a6e4be 3028. [bug] isc_sockaddr_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:18:44 +00:00
Mark Andrews 0b8c40c8d8 CHANGES 2011-02-21 06:18:03 +00:00
Automatic Updater 4455a07e1a update 2011-02-21 06:15:57 +00:00
Mark Andrews 30aaec2122 3027. [bug] Add documented REQUIREs to cfg_obj_asnetprefix() to
catch NULL pointer dereferences before they happen.
                        [RT #22521]
2011-02-21 06:07:49 +00:00
Mark Andrews 17a0bbda33 3026. [bug] lib/isc/httpd.c: check that we have enough space
after calling grow_headerspace() and if not
                        re-call grow_headerspace() until we do. [RT #22521]
2011-02-21 05:55:09 +00:00
Automatic Updater e06bc030b3 update 2011-02-21 00:16:49 +00:00
Mark Andrews aae88005f2 spelling 2011-02-21 00:06:57 +00:00
Automatic Updater cdb7ad6561 update 2011-02-20 01:15:55 +00:00
Mark Andrews 020120e3c7 spelling 2011-02-20 00:54:35 +00:00
Automatic Updater e6013156ef update 2011-02-20 00:16:54 +00:00
Automatic Updater d5a3595af8 update copyright notice 2011-02-19 23:47:38 +00:00
Automatic Updater 22efac9446 newcopyrights 2011-02-19 23:30:42 +00:00
Automatic Updater f03c1c0edf update 2011-02-19 02:16:31 +00:00
Evan Hunt b0c8948e37 Fixed incorrect library link order in libisccc and libisccfg 2011-02-19 01:30:52 +00:00
Evan Hunt 63b1c80af8 Fixed an error in change 3023, ensuring that journal file isn't
removed after IXFR.  No CHANGES note.
2011-02-19 01:24:46 +00:00
Automatic Updater 9e72291848 update 2011-02-19 00:16:51 +00:00
Automatic Updater 10aafc5aa3 update copyright notice 2011-02-18 23:47:25 +00:00
Michael Graff b7f0ab323d catch two unused function params, followup to RT#23310 2011-02-18 23:39:55 +00:00
Automatic Updater e6a6028987 newcopyrights 2011-02-18 23:30:49 +00:00
Evan Hunt b32e391602 3025. [bug] Fixed a possible deadlock due to zone resigning.
[RT #22964]
2011-02-18 23:26:44 +00:00
Automatic Updater ec519db9f2 auto update 2011-02-18 23:16:34 +00:00
Automatic Updater 38c3d881bb update 2011-02-18 23:15:40 +00:00
Michael Graff e3fbbde8fc spaces -> tabs 2011-02-18 23:04:31 +00:00
Michael Graff 52d44117c8 Remove RTT banding [RT 23310] 2011-02-18 22:55:31 +00:00
Automatic Updater 151a7c4e94 update 2011-02-18 22:15:48 +00:00
Evan Hunt 2870e5fb54 s/[func]/[test]/ for change #3019 2011-02-18 21:30:50 +00:00
Evan Hunt 1d5981dd3f 3023. [bug] Named could be left in an inconsistent state when
receiving multiple AXFR response messages that were
			not all TSIG-signed. [RT #23254]
2011-02-18 21:22:12 +00:00
Automatic Updater fcdbc61d18 update 2011-02-18 16:15:37 +00:00
Scott Mann 57b403c1e9 Fix prz SERVFAILs after failed zone transfers (RT23246). 2011-02-18 15:18:30 +00:00
Automatic Updater 6e2411592a update 2011-02-18 05:15:35 +00:00
Mark Andrews 9e4359b42e silence: warning: 'manager_log' defined but not used 2011-02-18 04:19:05 +00:00
Automatic Updater 7cced187a2 update 2011-02-18 00:16:45 +00:00
Automatic Updater 6885ca3220 update copyright notice 2011-02-17 23:47:24 +00:00
Automatic Updater bcad5c48c0 auto update 2011-02-17 23:16:14 +00:00
Automatic Updater d31e0e5764 update 2011-02-17 05:15:43 +00:00
Mark Andrews 293e500697 simplify zone_signwithkey call 2011-02-17 04:57:28 +00:00
Automatic Updater 6074716d63 update 2011-02-17 03:17:23 +00:00
Mark Andrews 19afa17960 ensure that the DNSKEY rrset get re-signed even if it hasn't been
updated in sign_apex.
2011-02-17 02:57:22 +00:00
Automatic Updater f0ba3b1e31 update 2011-02-16 20:15:45 +00:00
Evan Hunt 29bd52e4ee 3021. [bug] Change #3010 was incomplete. [RT #22296] 2011-02-16 19:48:12 +00:00
Automatic Updater eebee125a9 update 2011-02-16 00:16:57 +00:00
Automatic Updater c41b2924a5 update copyright notice 2011-02-15 23:47:36 +00:00
Automatic Updater c53a6f37de newcopyrights 2011-02-15 23:30:46 +00:00
Automatic Updater f3325b2631 auto update 2011-02-15 23:16:34 +00:00
Automatic Updater 11cf7d678e update 2011-02-15 22:15:44 +00:00
Mark Andrews b1b42b03b7 3020. [bug] auto-dnssec failed to correctly update the zone when changing the DNSKEY RRset. [RT #23232] 2011-02-15 22:02:36 +00:00
Automatic Updater 134deb3eda update 2011-02-15 19:15:34 +00:00
Francis Dupont 931814de4a typo in comment 2011-02-15 18:23:34 +00:00
Automatic Updater 0cb3f49d9e update 2011-02-15 00:16:59 +00:00
Mark Andrews c5fa370695 3019. [func] Test: check apex NSEC3 records after adding DNSKEY
record via UPDATE. [RT #23229]
2011-02-14 23:53:44 +00:00
Automatic Updater 53a530ddaa auto update 2011-02-14 23:16:59 +00:00
Automatic Updater 5e7d30c39d auto update 2011-02-11 23:16:50 +00:00
Automatic Updater b93f4fb82b auto update 2011-02-10 23:16:24 +00:00
Automatic Updater 3d3c6f73ef update 2011-02-08 23:17:38 +00:00
Automatic Updater 1914ea0df2 auto update 2011-02-08 23:16:44 +00:00
Automatic Updater 56748bc3d1 update copyright notice 2011-02-08 23:10:07 +00:00
Automatic Updater 5acd631070 newcopyrights 2011-02-08 23:07:19 +00:00
Automatic Updater e36a534a31 update 2011-02-08 04:16:54 +00:00
Mark Andrews 37b017f2ca Regression test for:
3018.   [bug]           Named failed to check for the "none;" acl when deciding
                        if a zone may need to be re-signed. [RT #23120]
2011-02-08 03:47:02 +00:00
Automatic Updater c098252bf4 update 2011-02-07 13:16:25 +00:00
Mark Andrews 74b7355f1e missing [ 2011-02-07 12:28:32 +00:00
Automatic Updater 5cc47f19a1 update 2011-02-07 00:16:51 +00:00
Mark Andrews 4d205bf79b 3018. [bug] Named failed to check for the "none;" acl when deciding
if a zone may need to be re-signed. RT #23120]
2011-02-07 00:11:05 +00:00
Mark Andrews 462a97981f CHANGES 2011-02-07 00:10:36 +00:00
Automatic Updater 4d32726dd1 update 2011-02-04 01:15:39 +00:00
Automatic Updater 79cf9524b1 regen HEAD 2011-02-04 01:14:16 +00:00
Automatic Updater 6cc8095d2f update 2011-02-03 13:16:39 +00:00
Automatic Updater 784a904bd0 update copyright notice 2011-02-03 12:18:12 +00:00
Automatic Updater 8ccd7da886 newcopyrights 2011-02-03 12:15:34 +00:00
Mark Andrews 5cfe4bcb0a 3017. [doc] dnssec-keyfromlabel -I was not properly documented.
[RT #22887]
2011-02-03 12:01:44 +00:00
Mark Andrews 5b79d15401 3016. [bug] rndc usage missing '-b'. [RT #22937] 2011-02-03 11:46:17 +00:00
Automatic Updater 4ea6ae20a7 update 2011-02-03 08:15:50 +00:00
Mark Andrews a8e5a59183 3015. [port] win32: fix IN6_IS_ADDR_LINKLOCAL and
IN6_IS_ADDR_SITELOCAL macros. [RT #22724]
2011-02-03 08:13:51 +00:00
Mark Andrews 69496e55a7 placeholder 2011-02-03 07:44:18 +00:00
Mark Andrews c1ee8bb4ba 3013. [bug] The DNS64 ttl was not always being set as expected.
[RT #23034]
2011-02-03 07:35:56 +00:00
Automatic Updater a3a75bc1fd update 2011-02-03 07:15:42 +00:00
Mark Andrews 63d9e735c4 spelling 2011-02-03 06:20:09 +00:00
Automatic Updater cc904e5c83 update 2011-02-03 06:15:40 +00:00
Mark Andrews 16cc4a1f56 3012. [bug] Remove DNSKEY TTL change pairs before generating
signing records for any remaing DNSKEY changes.
                        [RT #22590]
2011-02-03 06:03:15 +00:00
Mark Andrews 07cc752057 regen 2011-02-03 05:51:56 +00:00
Mark Andrews 000a8970f8 3011. [func] Change the default query timeout from 30 seconds
to 10.  Allow setting this in named.conf using the new
                        'resolver-query-timeout' option, which specifies a max
                        time in seconds.  0 means 'default' and anything longer
                        than 30 will be silently set to 30. [RT #22852]
2011-02-03 05:41:55 +00:00
Automatic Updater da6fe5c101 update 2011-02-03 01:15:42 +00:00
Evan Hunt 903b3c84e2 3010. [bug] Fixed a bug where "rndc reconfig" stopped the timer
for refreshing managed-keys. [RT #22296]
2011-02-03 00:21:55 +00:00
Automatic Updater 183234d5c4 update 2011-02-02 00:16:22 +00:00
Automatic Updater 2f76b9339e newcopyrights 2011-02-01 23:30:40 +00:00
Automatic Updater 6034d9bbaa auto update 2011-02-01 23:16:37 +00:00
Automatic Updater c11a2cf31f update 2011-02-01 20:15:34 +00:00
Evan Hunt 439a6b2fbf created cvsignore 2011-02-01 20:12:16 +00:00
Automatic Updater 02732414a9 auto update 2011-01-30 23:16:50 +00:00
Automatic Updater e2c942f6af auto update 2011-01-28 23:16:39 +00:00
Automatic Updater 310d6983fc update 2011-01-28 00:16:17 +00:00
Automatic Updater b720af4cd4 update copyright notice 2011-01-27 23:47:21 +00:00
Automatic Updater 3c761103e8 newcopyrights 2011-01-27 23:30:42 +00:00
Automatic Updater a26311e084 update 2011-01-27 03:16:56 +00:00
Mark Andrews 1fba20bd0b 3009. [bug] clients-per-query code didn't work as expected with
particular query patterns. [RT #22972]
2011-01-27 02:24:49 +00:00
Automatic Updater e8f20fbef4 update 2011-01-25 05:15:28 +00:00
Mark Andrews c656722ea7 whitespace 2011-01-25 04:27:38 +00:00
Automatic Updater 5eafc32634 auto update 2011-01-24 23:16:39 +00:00
Automatic Updater c8389abcf8 update 2011-01-23 01:15:32 +00:00
Automatic Updater 66edf659b7 regen HEAD 2011-01-23 01:14:18 +00:00
Automatic Updater cbb24dc55c update 2011-01-22 02:15:44 +00:00
Mark Andrews 6441e3675a recursion-only -> recursive-only 2011-01-22 01:21:05 +00:00
Automatic Updater 98a0438cd9 update 2011-01-21 01:15:28 +00:00
Automatic Updater f7b2875691 regen HEAD 2011-01-21 01:14:13 +00:00
Automatic Updater 9c8f5f5e18 update 2011-01-20 11:15:32 +00:00
Mark Andrews 7292ae531b spelling 2011-01-20 10:17:23 +00:00
Automatic Updater 71e4fae3bb update 2011-01-20 00:16:13 +00:00
Automatic Updater c674aacfd6 update copyright notice 2011-01-19 23:47:12 +00:00
Automatic Updater 16a8f020ff newcopyrights 2011-01-19 23:30:39 +00:00
Automatic Updater fb4fa49974 update 2011-01-19 03:16:41 +00:00
Mark Andrews f862994cbd explicitly initialise dump and restore 2011-01-19 03:09:14 +00:00
Automatic Updater 6ff513bc38 update 2011-01-17 05:15:31 +00:00
Mark Andrews ee931bc7a3 silence warning: integer overflow detected: op "<<" 2011-01-17 04:27:23 +00:00
Automatic Updater d0735483e5 update 2011-01-14 01:16:16 +00:00
Automatic Updater a09fff7051 update copyright notice 2011-01-14 00:51:43 +00:00
Automatic Updater 3de6db3208 newcopyrights 2011-01-14 00:49:37 +00:00
Mark Andrews 638614fe02 silence: warning: format not a string literal and no format arguments 2011-01-14 00:44:53 +00:00
Mark Andrews 2c18cb2e9a explicit initialisation 2011-01-14 00:33:32 +00:00
Automatic Updater a4bbf4d7cb update 2011-01-14 00:15:58 +00:00
Automatic Updater 3790d6b265 update 2011-01-13 23:16:45 +00:00
Mark Andrews cc5e0baaef arguements out of order 2011-01-13 23:16:06 +00:00
Automatic Updater 02973ab414 newcopyrights 2011-01-13 22:28:45 +00:00
Automatic Updater 520ea669ac update 2011-01-13 19:54:50 +00:00
Evan Hunt 5645e0c82a Automatically-added copyright text was breaking the RPZ test. 2011-01-13 19:30:41 +00:00
Automatic Updater 7c3c764c75 update 2011-01-13 10:16:03 +00:00
Mark Andrews 481ebd6977 rpz require -DBIND9 2011-01-13 09:53:04 +00:00
Automatic Updater 34f84b54ef update 2011-01-13 09:16:19 +00:00
Mark Andrews 17acd2a230 remove -I "../..../lib/dns/sec/openssl/include" 2011-01-13 08:56:45 +00:00
Automatic Updater 2352050890 update copyright notice 2011-01-13 08:50:29 +00:00
Automatic Updater c3fd32ed29 newcopyrights 2011-01-13 08:48:15 +00:00
Mark Andrews 16ae8f12c2 add -V to foreground flags 2011-01-13 08:46:34 +00:00
Mark Andrews 50fd8587a7 extra external symbols 2011-01-13 08:29:08 +00:00
Mark Andrews 6767b5b544 openssl include path 2011-01-13 08:15:30 +00:00
Automatic Updater f00a2f4d6e update 2011-01-13 08:15:25 +00:00
Mark Andrews 0a24e3a8ae openssl include path 2011-01-13 07:51:06 +00:00
Mark Andrews fd7b3477c3 openssl include path 2011-01-13 07:25:35 +00:00
Mark Andrews 000439ae98 isc_netaddr_getzone 2011-01-13 07:20:14 +00:00
Automatic Updater 51a510fd61 update 2011-01-13 07:15:28 +00:00
Mark Andrews 9e78a55d81 opensslgost_link.c 2011-01-13 07:12:14 +00:00
Mark Andrews 23784a729d dst_key_restory -> dst_key_restore 2011-01-13 07:06:50 +00:00
Mark Andrews 559b51e980 only look for sys/socket.h if we also have sys/un.h 2011-01-13 07:05:57 +00:00
Mark Andrews 93b81c6d0a explicit conversion from unsigned long to dns_rpz_cidr_bits_t 2011-01-13 06:48:14 +00:00
Mark Andrews 68f6e45d28 uint8_t -> unsigned char 2011-01-13 06:41:05 +00:00
Mark Andrews c3e9221f3b prototype mismatch 2011-01-13 06:36:04 +00:00
Mark Andrews 119f627c82 uint32_t -> isc_uint32_t 2011-01-13 06:29:16 +00:00
Mark Andrews 98455e2090 missing semi-colon 2011-01-13 06:21:15 +00:00
Automatic Updater d5a538a92a update 2011-01-13 06:15:26 +00:00
Mark Andrews 891b61c390 define HAVE_OPENSSL_GOST ENABLE_RPZ_NSDNAME ENABLE_RPZ_NSIP 2011-01-13 06:08:58 +00:00
Automatic Updater 19973813df 9.8.0b1 2011-01-13 05:25:47 +00:00
Automatic Updater 9d059cceef update 2011-01-13 05:16:36 +00:00
Automatic Updater 5329b4137e regen HEAD 2011-01-13 05:13:52 +00:00
Automatic Updater 9cee5bb028 update copyright notice 2011-01-13 04:59:26 +00:00
Automatic Updater 3f616e6f84 newcopyrights 2011-01-13 04:51:08 +00:00
Mark Andrews bde1625cbc rpz 2011-01-13 04:49:59 +00:00
Mark Andrews e02c1d738b 9.8.0b1 2011-01-13 04:45:17 +00:00
Mark Andrews a3eb8b33ec unsigned constants 2011-01-13 04:20:03 +00:00
Automatic Updater c2c4ca4c77 update 2011-01-13 04:16:09 +00:00
Mark Andrews 9d53927aa8 zone = NULL 2011-01-13 03:57:50 +00:00
Automatic Updater 32832d0597 update 2011-01-13 03:16:39 +00:00
Mark Andrews 6eba31815a #include <isc/print.h> 2011-01-13 03:03:31 +00:00
Mark Andrews a04b5f6794 spelling 2011-01-13 02:35:58 +00:00
Automatic Updater f7469b14f3 update 2011-01-13 02:16:31 +00:00
Mark Andrews 819f0ca24a regen 2011-01-13 02:06:40 +00:00
Mark Andrews 87708bde16 3008. [func] Response policy zones (RPZ) support. [RT #21726] 2011-01-13 01:59:28 +00:00
Automatic Updater 100b78748b update 2011-01-13 01:15:32 +00:00
Mark Andrews 38b84a1fcf 3007. [bug] Named failed to preserve the case of domain names in
rdata which is no compressable when writing master
                        files.  [RT #22863]
2011-01-13 00:55:49 +00:00
Automatic Updater b70c6fb6ff auto update 2011-01-12 23:16:51 +00:00
Automatic Updater e9eda341c9 update 2011-01-12 00:16:06 +00:00
Automatic Updater 135bcc2e42 update copyright notice 2011-01-11 23:47:14 +00:00
Automatic Updater b13d89bd89 newcopyrights 2011-01-11 23:30:36 +00:00
Automatic Updater e5b9f963cb update 2011-01-11 22:15:32 +00:00
Michael Graff 59b600ae73 commit Makefile.in, not Makefile 2011-01-11 21:40:35 +00:00
Michael Graff beb52a4b18 add tests for isc_atomic_xadd() and isc_atomic_xaddq() since there is some suspicion that they may not be working properly on all platforms. This is committed direclty to the mainline as it's only a test. I did not regenerate configure from configure.in, but just added the one Makefile line. Evan will take a quick look at this after it's committed. 2011-01-11 21:36:22 +00:00
Automatic Updater 1978971774 update 2011-01-11 00:16:30 +00:00
Automatic Updater 3e5340279d newcopyrights 2011-01-10 23:30:44 +00:00
Automatic Updater 031ba34331 auto update 2011-01-10 23:16:33 +00:00
Automatic Updater 46b5b52e16 update 2011-01-10 13:15:27 +00:00
Mark Andrews b053854c20 call dns_tsigkeyring_detach(&ring) 2011-01-10 13:09:49 +00:00
Automatic Updater 7d74de75b9 update 2011-01-10 08:15:30 +00:00
Mark Andrews adccda3b4c &dstkey -> dstkey 2011-01-10 07:38:22 +00:00
Automatic Updater e41e8a4fcf update 2011-01-10 06:15:30 +00:00
Mark Andrews 433e06a25c 3006. [func] Allow dynamically generated TSIG keys to be preserved
across restarts of named.  Initially this is for
                        TSIG keys generated using GSSAPI. [RT #22639]
2011-01-10 05:32:04 +00:00
Automatic Updater f0238aceb9 update 2011-01-10 05:15:33 +00:00
Mark Andrews fc5e97963d Check that ::1 is configured 2011-01-10 05:08:49 +00:00
Automatic Updater 21560605cc update 2011-01-10 04:15:54 +00:00
Mark Andrews 1403f9aa2f don't free memory passed to putenv(), use malloc and check for malloc failures 2011-01-10 03:49:49 +00:00
Automatic Updater 90482b5ba2 update 2011-01-09 00:16:27 +00:00
Automatic Updater 0e0be796a7 update copyright notice 2011-01-08 23:47:01 +00:00
Automatic Updater 572cb2c1c9 newcopyrights 2011-01-08 23:30:38 +00:00
Automatic Updater ad857789e8 auto update 2011-01-08 23:16:51 +00:00
Automatic Updater e189b22094 update 2011-01-08 02:15:43 +00:00
Evan Hunt b156001ec1 Oops, omitted some commits from change #3005. 2011-01-08 01:26:01 +00:00
Automatic Updater 65ad89971e regen HEAD 2011-01-08 01:15:44 +00:00
Automatic Updater e24e47f8ae update 2011-01-08 01:15:27 +00:00
Evan Hunt 8a743600dd 3005. [port] Solaris: Work around the lack of
gsskrb5_register_acceptor_identity() by setting
			the KRB5_KTNAME environment variable to the
			contents of tkey-gssapi-keytab.  Also fixed
			test errors on MacOSX.  [RT #22853]
2011-01-08 00:33:12 +00:00
Automatic Updater b88393d56d update 2011-01-08 00:16:22 +00:00
Automatic Updater 93235c1cba update copyright notice 2011-01-07 23:47:07 +00:00
Automatic Updater 765c97d56c newcopyrights 2011-01-07 23:30:34 +00:00
Automatic Updater 2ebb8eda0b auto update 2011-01-07 23:16:41 +00:00
Automatic Updater 197c7a5351 update 2011-01-07 22:15:30 +00:00
Evan Hunt a727690e8b HPUX: silence compiler warnings about signed/unsigned comparisons 2011-01-07 21:42:03 +00:00
Automatic Updater f01cd4dc50 update 2011-01-07 07:15:28 +00:00
Evan Hunt f9303c6db0 added missing .cvsignore entry 2011-01-07 07:11:41 +00:00
Evan Hunt f686c5d700 Added missing .cvsignore entries 2011-01-07 07:10:34 +00:00
Evan Hunt c23a9eed3e - Missed out authsock.pl when committing 3003.
- Remove auth.sock in clean.sh.
2011-01-07 07:01:58 +00:00
Automatic Updater 54cd2bb9d9 update 2011-01-07 06:15:31 +00:00
Evan Hunt 3df7f5a9d6 add ssu_external.c to win32 definitions 2011-01-07 05:32:49 +00:00
Evan Hunt 4ac6a44512 Forgot to add ssu_external.c when committing change #3003. 2011-01-07 05:29:08 +00:00
Automatic Updater b432da33fe update 2011-01-07 05:15:38 +00:00
Mark Andrews dc4fa197dd 3004. [func] DNS64 reverse support. [RT #22769] 2011-01-07 04:31:39 +00:00
Automatic Updater 26dffbd206 update 2011-01-07 01:15:32 +00:00
Automatic Updater 610cd6f845 regen HEAD 2011-01-07 01:13:04 +00:00
Evan Hunt 5a87f3439e Initialize a pointer to NULL in order to to silence a compiler warning.
Committing without review because the change is trivial.
2011-01-07 00:50:06 +00:00
Automatic Updater a02bf5420c update 2011-01-07 00:16:38 +00:00
Automatic Updater db69d5d53c update copyright notice 2011-01-06 23:47:00 +00:00
Automatic Updater 099b86fb81 newcopyrights 2011-01-06 23:30:38 +00:00
Evan Hunt 3916872f37 3003. [experimental] Added update-policy match type "external",
enabliing named to defer the decision of whether to
			allow a dynamic update to an external daemon.
			(Contributed by Andrew Tridgell.) [RT #22758]
2011-01-06 23:24:39 +00:00
Automatic Updater 419a6c5ae4 update 2011-01-06 00:16:28 +00:00
Automatic Updater db85439621 newcopyrights 2011-01-05 23:30:47 +00:00
Automatic Updater 9412850a75 regen 2011-01-05 23:30:46 +00:00
Automatic Updater e575ca66b2 update 2011-01-05 01:15:29 +00:00
Automatic Updater dcfda24abf regen HEAD 2011-01-05 01:14:09 +00:00
Automatic Updater 0166a1879a update 2011-01-05 00:16:10 +00:00
Automatic Updater 1da9dbcf48 update copyright notice 2011-01-04 23:47:14 +00:00
Automatic Updater 229ea4644b newcopyrights 2011-01-04 23:30:38 +00:00
Automatic Updater a184761e52 regen 2011-01-04 23:30:37 +00:00
Automatic Updater 4e4a9d2121 update 2011-01-04 05:15:44 +00:00
Mark Andrews 161429fc05 3002. [bug] isc_mutex_init_errcheck() failed to destroy attr.
[RT #22766]
2011-01-04 04:32:13 +00:00
Automatic Updater 3466bcb725 update 2011-01-04 01:15:27 +00:00
Automatic Updater ebabe300b6 regen HEAD 2011-01-04 01:14:09 +00:00
Automatic Updater 08227c5ccb update 2011-01-04 00:16:07 +00:00
Evan Hunt 79bf7c874b 3001. [func] Added a default trust anchor for the root zone, which
can be switched on by setting "dnssec-validation auto;"
			in the named.conf options. [RT #21727]
2011-01-03 23:45:08 +00:00
Automatic Updater f098c65191 update 2010-12-27 14:15:30 +00:00
Mark Andrews ac78c47210 ! test -n -> test -z 2010-12-27 13:38:43 +00:00
Automatic Updater 14ffe33506 update 2010-12-27 00:16:12 +00:00
Mark Andrews c2f37a77cc #include ISC_PLATFORM_KRB5HEADER [RT #22798] 2010-12-26 23:24:18 +00:00
Automatic Updater dde1d911c1 update 2010-12-26 01:15:26 +00:00
Automatic Updater 66f25f2cee regen HEAD 2010-12-26 01:14:08 +00:00
Automatic Updater 89345e4c24 update 2010-12-25 22:15:24 +00:00
Mark Andrews 5aaac798d8 s;<command/>;</command>; 2010-12-25 22:01:35 +00:00
Automatic Updater 1fdedb1584 update 2010-12-25 00:16:31 +00:00
Automatic Updater 6764a1403a update copyright notice 2010-12-24 23:47:05 +00:00
Automatic Updater 348040cb26 newcopyrights 2010-12-24 23:30:29 +00:00
Automatic Updater 8a75f38e1d update 2010-12-24 08:15:26 +00:00
Mark Andrews cd86950664 exit 255 2010-12-24 07:27:15 +00:00
Automatic Updater 11234b877c update 2010-12-24 03:16:37 +00:00
Evan Hunt d9ad0a55bb 3000. [bug] More TKEY/GSS fixes:
- nsupdate can now get the default realm from
			   the user's Kerberos principal
			 - corrected gsstest compilation flags
			 - improved documentation
			 - fixed some NULL dereferences
			[RT #22795]
2010-12-24 02:20:47 +00:00
Automatic Updater 988e9fd7c0 update 2010-12-24 01:15:29 +00:00
Automatic Updater 0e9e255d16 regen HEAD 2010-12-24 01:14:21 +00:00
Automatic Updater 1b7daed82b update 2010-12-24 00:16:35 +00:00
Automatic Updater a094c46640 update copyright notice 2010-12-23 23:47:08 +00:00
Automatic Updater 95cfad51a3 newcopyrights 2010-12-23 23:30:34 +00:00
Automatic Updater 62aefa60b7 update 2010-12-23 04:16:04 +00:00
Mark Andrews 9fffc937a9 rege 2010-12-23 04:09:28 +00:00
Mark Andrews 37dee1ff94 2999. [func] Add GOST support (RFC 5933). [RT #20639] 2010-12-23 04:08:00 +00:00
Automatic Updater 5c92589c90 update 2010-12-23 00:16:36 +00:00
Automatic Updater 557919588b update copyright notice 2010-12-22 23:46:59 +00:00
Automatic Updater 415827fa64 newcopyrights 2010-12-22 23:30:34 +00:00
Automatic Updater 41204e2f0f update 2010-12-22 13:15:26 +00:00
Mark Andrews 777b848142 2998. [func] Add isc_task_beginexclusive and isc_task_endexclusive
to the task api. [RT #22776]
2010-12-22 13:05:20 +00:00
Automatic Updater 0f6c33adb2 update 2010-12-22 09:15:38 +00:00
Mark Andrews 10e018f66d s/ISC_OPENSSL_INC/DST_OPENSSL_INC 2010-12-22 09:00:40 +00:00
Automatic Updater 3962b1c955 update 2010-12-22 06:15:30 +00:00
Mark Andrews 7a54dadeb5 2998. [func] Add isc_task_beginexclusive and isc_task_endexclusive
to the task api. [RT #22776]
2010-12-22 05:19:02 +00:00
Automatic Updater b427cc266d update 2010-12-22 04:16:39 +00:00
Mark Andrews 78fcac2f19 2997. [func] named -V now reports the OpenSSL and libxml2 verions
it was compiled against. [RT #22687]
2010-12-22 04:05:41 +00:00
Mark Andrews 643935ac11 2997. [func] named -V now reports the OpenSSL and libxml2 verions
it was compiled against. [RT #22687]
2010-12-22 03:59:02 +00:00
Automatic Updater 687baa4f94 update 2010-12-22 03:16:24 +00:00
Mark Andrews 79344b9710 2996. [security] Temporarily disable SO_ACCEPTFILTER support.
[RT #22589]
2010-12-22 03:08:36 +00:00
Mark Andrews 179e028b35 2995. [bug] The Kerberos realm was not being correctly extracted
from the signer's identity. [RT #22770]
2010-12-22 02:33:12 +00:00
Automatic Updater 69c3b3c057 update 2010-12-22 01:15:23 +00:00
Automatic Updater 4cfcf67f81 regen HEAD 2010-12-22 01:14:07 +00:00
Automatic Updater 3b3e7fe622 update 2010-12-22 00:16:39 +00:00
Automatic Updater 8868ef9c64 update copyright notice 2010-12-21 23:47:08 +00:00
Automatic Updater a3fdc395a6 newcopyrights 2010-12-21 23:30:37 +00:00
Automatic Updater f2c99a20e3 update 2010-12-21 23:15:28 +00:00
Jeremy Reed 7c6972d6ca Remove duplicated check-mx explanation.
Ebersman told me about it.
I opened ticket #22778 for this.
2010-12-21 22:40:55 +00:00
Automatic Updater ea2d37e4f1 update 2010-12-21 05:15:41 +00:00
Mark Andrews bc650d355c regen 2010-12-21 04:31:27 +00:00
Mark Andrews c2170a4bd0 2994. [port] NetBSD: use pthreads by default on NetBSD >= 5.0, and
do not use threads on earlier versions.  Also kill
                        the unproven-pthreads, mit-pthreads, and ptl2 support.
2010-12-21 04:20:23 +00:00
Automatic Updater e1f024416a update 2010-12-21 03:16:10 +00:00
Mark Andrews 82f77687ab 2993. [func] Dynamically grow adb hash tables. [RT #21186] 2010-12-21 03:11:42 +00:00
Mark Andrews 72be2e5698 regen 2010-12-21 02:33:59 +00:00
Mark Andrews 0ece47f7c1 2992. [contrib] contrib/check-secure-delegation.pl: A simple tool
for looking at a secure delegation. [RT #22059]
2010-12-21 02:32:21 +00:00
Mark Andrews 1f512cd06b 2991. [contrib] contrib/zone-edit.sh: A simple zone editing tool for
dynamic zones. [RT #22365]
2010-12-21 02:19:06 +00:00
Automatic Updater 66b2016a91 update 2010-12-21 00:16:11 +00:00
Automatic Updater ca103999e6 update copyright notice 2010-12-20 23:47:21 +00:00
Automatic Updater 6a71702b47 auto update 2010-12-20 23:17:15 +00:00
Automatic Updater 42bb7bf869 update 2010-12-20 22:15:24 +00:00
Evan Hunt 950aa1d752 When a prereq.sh file determines that a test can't run because the feature
to be tested was not configured in at build time, it can now return 255,
and run.sh will print "R:SKIPPED" instead of "R:UNTESTED".  Robie will be
able to flag this as green rather than yellow.
2010-12-20 21:35:45 +00:00
Automatic Updater d39a94a1db update 2010-12-20 19:15:29 +00:00
Evan Hunt 8fda09fc85 Changed $(command) to command in tests.sh for compatibility with
older bourne shells.
2010-12-20 18:37:07 +00:00
Automatic Updater 72cfc80dab update 2010-12-20 00:16:14 +00:00
Automatic Updater f7a71eef29 tsiggss dlzexternal 2010-12-19 23:50:14 +00:00
Mark Andrews e11d10bbcc example.nil.zone -> example.nil.db 2010-12-19 23:39:28 +00:00
Automatic Updater 50e524aa29 update 2010-12-19 22:15:29 +00:00
Evan Hunt db4c1bc48a Looks like "ifdef" should have been "ifndef". (Committing without review to
silence robie.)
2010-12-19 21:32:35 +00:00
Automatic Updater 8b840548ca update 2010-12-19 08:15:33 +00:00
Evan Hunt 584ad7dedd 2990. [bug] 'dnssec-settime -S' no longer tests prepublication
interval validity when the interval is set to 0.
			[RT #22761]
2010-12-19 07:29:36 +00:00
Automatic Updater 8ff031ed05 update 2010-12-19 03:16:40 +00:00
Evan Hunt c445b2f648 Add #ifdef BIND9 to some of the new DLZ code to fix link errors
when building with --enable-exportlibs
2010-12-19 02:51:41 +00:00
Evan Hunt 9f453d9342 removed unnecessary "done" log message from dns_sdlzcreate(); it used
__FUNCTION__ which caused problems on some compilers.
2010-12-19 02:37:08 +00:00
Automatic Updater dcaa912725 update 2010-12-19 01:15:28 +00:00
Automatic Updater 517ae3de96 regen HEAD 2010-12-19 01:14:08 +00:00
Automatic Updater 7bd57e7372 update 2010-12-19 00:16:32 +00:00
Automatic Updater 941c0792f2 update copyright notice 2010-12-18 23:47:11 +00:00
Automatic Updater 98179904c3 update 2010-12-18 17:15:25 +00:00
Evan Hunt 6c3eff861d tsiggss test needed a prereq.sh file. (Committing without review because
the script is simple, no one is available, and I want to shut robie up.)
2010-12-18 16:48:41 +00:00
Automatic Updater ec310af18b update 2010-12-18 15:15:24 +00:00
Mark Andrews aa5b977943 regen 2010-12-18 14:47:42 +00:00
Mark Andrews c880d51849 gsskrb5_register_acceptor_identity is not available on all platforms 2010-12-18 14:46:21 +00:00
Automatic Updater 009b1debed update 2010-12-18 12:15:25 +00:00
Mark Andrews 6dcb804dc6 UNUSED(use_static_stub); 2010-12-18 11:47:13 +00:00
Mark Andrews 0faa11ab77 clean first 2010-12-18 11:45:01 +00:00
Automatic Updater 2aea9329b6 update 2010-12-18 10:15:29 +00:00
Automatic Updater 8aa53dcb1d staticstub 2010-12-18 09:41:37 +00:00
Automatic Updater 819d54a570 update 2010-12-18 02:16:16 +00:00
Evan Hunt af903e5008 Added files to clean.sh scripts that have been left around after tests run.
Skipping the ticket/review steps because the change is trivial.
2010-12-18 02:12:44 +00:00
Evan Hunt 71bd858d8e 2989. [func] Added support for writable DLZ zones. (Contributed
by Andrew Tridgell of the Samba project.) [RT #22629]

2988.	[experimental]	Added a "dlopen" DLZ driver, allowing the creation
			of external DLZ drivers that can be loaded as
			shared objects at runtime rather than linked with
			named.  Currently this is switched on via a
			compile-time option, "configure --with-dlz-dlopen".
			Note: the syntax for configuring DLZ zones
			is likely to be refined in future releases.
			(Contributed by Andrew Tridgell of the Samba
			project.) [RT #22629]

2987.	[func]		Improve ease of configuring TKEY/GSS updates by
			adding a "tkey-gssapi-keytab" option.  If set,
			updates will be allowed with any key matching
			a principal in the specified keytab file.
			"tkey-gssapi-credential" is no longer required
			and is expected to be deprecated.  (Contributed
			by Andrew Tridgell of the Samba project.)
			[RT #22629]
2010-12-18 01:56:23 +00:00
Automatic Updater 21b13993dc update 2010-12-18 00:16:33 +00:00
Automatic Updater b65282d612 auto update 2010-12-17 23:16:55 +00:00
Automatic Updater 15c1f38755 update 2010-12-17 04:16:05 +00:00
Mark Andrews ffa806a294 fix change numbers 2010-12-17 03:21:10 +00:00
Automatic Updater fa1c5519fd update 2010-12-17 01:15:29 +00:00
Automatic Updater b6f3a9131e regen HEAD 2010-12-17 01:14:04 +00:00
Mark Andrews 273757406a .zone -> .db 2010-12-17 00:57:39 +00:00
Automatic Updater 8a40052676 update 2010-12-17 00:16:34 +00:00
Automatic Updater 0ccd663a83 update copyright notice 2010-12-16 23:47:08 +00:00
Automatic Updater 4482fc347c auto update 2010-12-16 23:16:54 +00:00
Automatic Updater 1027681624 update 2010-12-16 10:15:29 +00:00
Tatuya JINMEI 神明達哉 743bbdc18f 2947. [func] Add new zone type "static-stub". It's like a stub
zone, but the nameserver names and/or their IP
			addresses are statically configured. [RT #21474]

(for 9.8.0)
2010-12-16 09:51:30 +00:00
Automatic Updater 68918cc072 auto update 2010-12-15 23:16:50 +00:00
Automatic Updater c00580a734 update 2010-12-15 19:15:27 +00:00
Evan Hunt bbedadf76a 2985. [bug] Add a regression test for change #2896. [RT #21324] 2010-12-15 18:44:37 +00:00
Automatic Updater 47d4a3b457 update 2010-12-14 01:15:32 +00:00
Mark Andrews 8d8f0b4659 2984. [bug] Don't run MX checks when the target of the MX record is ".". [RT #22645] 2010-12-14 00:39:59 +00:00
Automatic Updater 2ed508c655 auto update 2010-12-13 23:16:47 +00:00
Automatic Updater 1c76184b2a update 2010-12-10 20:15:30 +00:00
johnd 858c4a86c1 Fixed positioning of change description in CHANGES 2010-12-10 20:03:43 +00:00
johnd 7659fdb3aa Include "loadkeys" in rndc help output. [RT #22493] 2010-12-10 19:20:47 +00:00
Automatic Updater 7872a10b39 update 2010-12-10 01:15:22 +00:00
Mark Andrews a16d8521e4 re-base the api version for 9.8 2010-12-10 01:13:02 +00:00
Automatic Updater 7b3b32ea6d auto update 2010-12-09 23:16:37 +00:00
Automatic Updater c15fc34dde update 2010-12-09 08:16:09 +00:00
Automatic Updater 5a28dc400e newcopyrights 2010-12-09 07:32:01 +00:00
Automatic Updater abea197a5f update 2010-12-09 07:15:23 +00:00
Mark Andrews cf5770e7b1 remove semi-colon 2010-12-09 06:17:33 +00:00
Automatic Updater f4177a8d44 update 2010-12-09 06:15:24 +00:00
Mark Andrews 391b2f42eb dns64 2010-12-09 06:12:43 +00:00
Mark Andrews 187d99dc53 s/dev/sdev/ 2010-12-09 06:08:05 +00:00
Automatic Updater e3930b84cf update 2010-12-09 05:16:31 +00:00
Mark Andrews 44c0cfd2be remove extraneos semicolon 2010-12-09 04:59:09 +00:00
Mark Andrews 987f2097a6 dns64 is BIND9 only 2010-12-09 04:53:48 +00:00
Automatic Updater 3a790f1a34 9.8.0a1 2010-12-09 04:44:56 +00:00
Mark Andrews 73dbd4e933 9.8.0a1 2010-12-09 04:39:10 +00:00
Automatic Updater fd6a9d688c update copyright notice 2010-12-09 04:31:57 +00:00
Automatic Updater d1cb7c4f74 newcopyrights 2010-12-09 04:29:55 +00:00
Mark Andrews b44bb86068 add comment 2010-12-09 04:17:15 +00:00
Automatic Updater 655878ed91 update 2010-12-09 04:16:03 +00:00
Mark Andrews 1e442d1994 zero bind 64 to 71 if prefix len is 64 2010-12-09 04:01:43 +00:00
Automatic Updater b68a79c329 update 2010-12-09 01:15:47 +00:00
Automatic Updater d893c62484 regen HEAD 2010-12-09 01:14:12 +00:00
Mark Andrews 9f9b7f0e8d 2982. [bug] Reference count dst keys. dst_key_attach() can be used
increment the reference count.

                        Note: dns_tsigkey_createfromkey() callers should now
                        always call dst_key_free() rather than setting it
                        to NULL on success. [RT #22672]
2010-12-09 00:54:34 +00:00
Automatic Updater c2ebdf2c49 update 2010-12-09 00:16:08 +00:00
Automatic Updater b8a9a7bef2 update copyright notice 2010-12-08 23:51:56 +00:00
Automatic Updater ead8aa3182 newcopyrights 2010-12-08 23:48:44 +00:00
Mark Andrews 7f9f8c13c5 support good*.conf bad*.conf 2010-12-08 23:47:25 +00:00
Automatic Updater 60073ed455 auto update 2010-12-08 23:16:36 +00:00
Automatic Updater b470dc92cd update 2010-12-08 05:15:29 +00:00
Mark Andrews b9f2d007c5 2981. [func] Partial DNS64 support (AAAA synthesis). [RT #21991] 2010-12-08 05:01:00 +00:00
Automatic Updater 69c4159e71 update 2010-12-08 03:16:30 +00:00
Mark Andrews e334405421 2981. [func] Partial DNS64 support (AAAA synthesis). [RT #21991] 2010-12-08 02:46:17 +00:00
Automatic Updater b59e6107bf update 2010-12-08 00:16:08 +00:00
Automatic Updater a4b8846651 update copyright notice 2010-12-07 23:47:02 +00:00
Automatic Updater cd839f5cf5 newcopyrights 2010-12-07 23:30:33 +00:00
Automatic Updater 9c007d5357 update 2010-12-07 03:16:29 +00:00
Mark Andrews 8aee18709f 2980. [bug] named didn't properly handle UPDATES that changed the
TTL of the NSEC3PARAM RRset. [RT #22363]
2010-12-07 02:53:34 +00:00
Automatic Updater 631e4420e1 update 2010-12-04 23:15:29 +00:00
Mark Andrews ab39760512 silence warning. temporary 2010-12-04 22:27:29 +00:00
Automatic Updater 4d03133c8f update 2010-12-04 14:15:30 +00:00
Mark Andrews b286683ae8 temporally make isc__task_exiting become isc_task_exiting so that the
export version of libisc has all the symbols to link.
2010-12-04 13:25:59 +00:00
Automatic Updater b512b5b533 update 2010-12-04 00:16:33 +00:00
Automatic Updater 59b283de0a update copyright notice 2010-12-03 23:46:46 +00:00
Automatic Updater edd5217152 newcopyrights 2010-12-03 23:30:56 +00:00
Automatic Updater 7c0d9e68f9 auto update 2010-12-03 23:16:47 +00:00
Automatic Updater 696195c373 update 2010-12-03 22:15:35 +00:00
Evan Hunt e78c2b856b 2979. [bug] named could deadlock during shutdown if two
"rndc stop" commands were issued at the same
			time. [RT #22108]
2010-12-03 22:05:19 +00:00
Mark Andrews 310e10d536 pass the address of dstkey 2010-12-03 21:47:19 +00:00
Automatic Updater 3cc6284383 update 2010-12-03 12:15:28 +00:00
Mark Andrews cc83084441 s/dns_key_free/dst_key_free/ 2010-12-03 12:03:22 +00:00
Automatic Updater 7a7c5c129c update 2010-12-03 01:15:38 +00:00
Mark Andrews c0a76b3c0b 2978. [port] hpux: look for <devpoll.h> [RT #21919] 2010-12-03 00:57:57 +00:00
Mark Andrews 82f0630bae 2977. [bug] 'nsupdate -l' report if the session key is missing.
[RT #21670]
2010-12-03 00:37:33 +00:00
Mark Andrews 6c9e21b4ce remove CVSS scores 2010-12-03 00:31:39 +00:00
Automatic Updater 312b3af169 update 2010-12-03 00:16:28 +00:00
Mark Andrews b44b120c66 update RT number 2010-12-03 00:09:53 +00:00
Automatic Updater 326a702a35 update copyright notice 2010-12-02 23:46:56 +00:00
Mark Andrews 36fc19f939 update 2976 description 2010-12-02 23:44:28 +00:00
Automatic Updater da24e725ff newcopyrights 2010-12-02 23:30:41 +00:00
Mark Andrews c87f15dac8 2976. [bug] named die on exit after negotiating a GSS-TSIG key. [RT #3415] 2010-12-02 23:22:42 +00:00
Automatic Updater 7fb319204e auto update 2010-12-02 23:16:39 +00:00
Automatic Updater a1eabc2b3f update 2010-12-02 05:16:36 +00:00
Mark Andrews 97664670d0 2975. [bug] rbtdb.c:cleanup_dead_nodes_callback() aquired the
wrong lock which could lead to server deadlock.
                        [RT #22614]
2010-12-02 04:58:13 +00:00
Automatic Updater 3a54e5ab6c update 2010-12-01 00:16:13 +00:00
Automatic Updater e085624e0f update copyright notice 2010-11-30 23:46:55 +00:00
Automatic Updater 5f0d1e7b82 newcopyrights 2010-11-30 23:30:34 +00:00
Automatic Updater c93b0eedee auto update 2010-11-30 23:16:39 +00:00
Automatic Updater 625a52bf35 update 2010-11-30 03:16:34 +00:00
Evan Hunt b5b934a0bb 2974. [bug] Some vaild UPDATE requests could fail due to a
consistency check examining the existing version
			of the zone rather than the new version resulting
			from the UPDATE. [RT #22413]
2010-11-30 02:27:08 +00:00
Automatic Updater d80e5e2db1 auto update 2010-11-29 23:16:40 +00:00
Automatic Updater d7f9d063f2 update 2010-11-25 05:15:54 +00:00
Mark Andrews 9f4f189847 CVE-2010-3613 Reduce complexity from M to L raising score from 7.1 to 7.8.
Just have the base CVSS vectors.
2010-11-25 04:44:36 +00:00
Automatic Updater fab04c267f auto update 2010-11-24 23:16:46 +00:00
Automatic Updater 7b7c25290f auto update 2010-11-19 23:16:40 +00:00
Automatic Updater ce74e6c3b4 update 2010-11-19 00:16:39 +00:00
Mark Andrews 5af195d1db 2973. [bug] bind.keys.h was being removed by the "make clean"
at the end of configure resulting in build failures
                        where there is very old version of perl installed.
                        Move it to "make maintainer-clean". [RT #22230]
2010-11-18 23:20:15 +00:00
Automatic Updater 22f9090a35 auto update 2010-11-18 23:16:39 +00:00
Automatic Updater 735be4878f update 2010-11-18 03:16:45 +00:00
Mark Andrews 7ffe86618c add CVE, VU and CVSS 2010-11-18 02:47:48 +00:00
Automatic Updater bed39bdf3a update 2010-11-18 01:16:38 +00:00
Automatic Updater bc7051ee3f update copyright notice 2010-11-18 00:59:43 +00:00
Mark Andrews 5a636f9951 2972. [bug] win32: address windows socket errors. [RT #21906] 2010-11-18 00:24:00 +00:00
Automatic Updater fa1d4d0cd7 update 2010-11-18 00:16:21 +00:00
Automatic Updater 33cc94f04c update copyright notice 2010-11-17 23:47:09 +00:00
Automatic Updater 44e3b27290 newcopyrights 2010-11-17 23:30:40 +00:00
Automatic Updater 231faefc5c update 2010-11-17 04:16:23 +00:00
Mark Andrews 1f50a0a441 handle namedxx.conf 2010-11-17 03:16:21 +00:00
Automatic Updater 1718ef8379 update 2010-11-17 01:15:40 +00:00
Evan Hunt 8eb30f8dd3 2971. [bug] Fixed a bug that caused journal files not to be
compacted on Windows systems as a result of
			non-POSIX-compliant rename() semantics. [RT #22434]
2010-11-17 00:27:54 +00:00
Automatic Updater 412e1fba75 update 2010-11-17 00:16:26 +00:00
Automatic Updater 42f95abecc auto update 2010-11-16 23:16:46 +00:00
Automatic Updater 10f0c5e041 update 2010-11-16 07:15:32 +00:00
Mark Andrews d48730a446 2970. [security] Adding a NO DATA negative cache entry failed to clear
any matching RRSIG records.  A subsequent lookup of
                        of NO DATA cache entry could trigger a INSIST when the
                        unexpected RRSIG was also returned with the NO DATA
                        cache entry.  [RT #22288]
2010-11-16 06:46:44 +00:00
Automatic Updater 70eef362e6 update 2010-11-16 06:15:29 +00:00
Mark Andrews cd9d825a71 remove accidental commit 2010-11-16 05:38:31 +00:00
Automatic Updater 33453d8676 update 2010-11-16 02:16:31 +00:00
Shawn Routhier 380c874925 Fix acl type processing so that allow-query works in options and view
statements.  Also add a new set of tests to verify proper functioning.
[RT #22418]
2010-11-16 01:37:39 +00:00
Automatic Updater f02bcd6262 update 2010-11-16 01:15:26 +00:00
Mark Andrews a27b3757fd 2968. [security] Named could fail to prove a data set was insecure
before marking it as insecure.  One set of conditions
                        that can trigger this occurs naturally when rolling
                        DNSKEY algorithms.  [RT #22309]
2010-11-16 01:14:51 +00:00
Mark Andrews 7965c00ca8 check for size equal zero in _format(), replace snprintf of a fixed string with strlcpy 2010-11-16 00:53:36 +00:00
Mark Andrews 432e1ce402 check that grow_headerspace added enough space or re-call it 2010-11-16 00:51:41 +00:00
Mark Andrews c5a3400f23 REQUIRE that rataset/rdatalist be non NULL 2010-11-16 00:50:28 +00:00
Mark Andrews a158495f84 INSIST that bucket in no longer ISC_ADB_INVALIDBUCKET after find_*_and_lock calls 2010-11-16 00:49:18 +00:00
Mark Andrews f85281de08 check for snprintf failure 2010-11-16 00:47:48 +00:00
Mark Andrews 73b1b8a6f1 safecpy -> strlcpy 2010-11-16 00:46:39 +00:00
Mark Andrews 2bd3a6e266 strncpy + array[end] = 0 -> strlcpy 2010-11-16 00:46:00 +00:00
Mark Andrews c2f5ddeeec isc_netaddr_format() check for sies equal 0 2010-11-16 00:43:02 +00:00
Mark Andrews baab444222 isc_sockaddr_format() check for sies equal 0 2010-11-16 00:42:35 +00:00
Mark Andrews d775887f01 cfg_obj_asnetprefix() check that the destinations are non NULL before writing to them 2010-11-16 00:41:32 +00:00
Automatic Updater 7b87980ae4 update 2010-11-10 09:15:26 +00:00
Mark Andrews d009bf089b new draft 2010-11-10 08:59:26 +00:00
Automatic Updater ab900cbf0d auto update 2010-11-08 23:16:36 +00:00
Automatic Updater 0575faaa41 auto update 2010-11-04 23:16:45 +00:00
Automatic Updater 649345de09 auto update 2010-11-03 23:16:39 +00:00
Automatic Updater e2e19bd90f update 2010-11-03 01:15:27 +00:00
Mark Andrews 7964553eb4 branch snapshots 2010-11-03 01:04:36 +00:00
Automatic Updater ad6f23f3ef auto update 2010-11-01 23:16:51 +00:00
Automatic Updater 717988cd08 auto update 2010-10-30 23:17:02 +00:00
Automatic Updater 9ba813582b auto update 2010-10-26 23:16:35 +00:00
Automatic Updater b20c38829d auto update 2010-10-25 23:16:39 +00:00
Automatic Updater d749f780d4 update 2010-10-20 00:16:21 +00:00
Automatic Updater 4071d667be update copyright notice 2010-10-19 23:47:10 +00:00
Automatic Updater e311702a89 newcopyrights 2010-10-19 23:30:33 +00:00
Automatic Updater 088245273f update 2010-10-19 03:16:23 +00:00
Mark Andrews c9c2ffe729 2967. [bug] 'host -D' now turns on debugging messages earlier.
[RT #22361]
2010-10-19 02:48:17 +00:00
Automatic Updater 51bc77127c update 2010-10-19 00:16:41 +00:00
Automatic Updater b3ff8e5ae7 update copyright notice 2010-10-18 23:47:08 +00:00
Automatic Updater b16e2045ac newcopyrights 2010-10-18 23:30:34 +00:00
Automatic Updater 5411715767 update 2010-10-18 04:16:39 +00:00
Mark Andrews 7bce336186 2966. [bug] isc_print_vsnprintf() failed to check if there was
space available in the buffer when adding a left
                        justified character with a non zero width,
                        (e.g. "%-1c"). [RT #22270]
2010-10-18 03:59:05 +00:00
Automatic Updater 003a8945fe auto update 2010-10-15 23:16:35 +00:00
Automatic Updater caafaf2813 auto update 2010-10-12 23:16:42 +00:00
Mark Andrews d9686e346b update 2010-10-11 23:24:45 +00:00
Automatic Updater 13cd516991 auto update 2010-10-07 23:16:35 +00:00
Automatic Updater 4d7f39b621 update 2010-10-04 23:15:38 +00:00
Mark Andrews 13dae6ff58 silence 'Null terminator in string initializer ignored.' warning 2010-10-04 22:27:41 +00:00
Automatic Updater 634d31cb04 update 2010-10-02 07:15:26 +00:00
Mark Andrews fadef3ce7e new draft 2010-10-02 06:54:51 +00:00
Automatic Updater 6e0d41fc62 auto update 2010-09-30 23:16:43 +00:00
Automatic Updater 2bb389f9a4 update 2010-09-30 01:15:27 +00:00
Mark Andrews 45fbce9f17 custom_WALMART_v9_7_2 2010-09-30 00:17:29 +00:00
Automatic Updater cb05fd5e8f update 2010-09-30 00:16:23 +00:00
Automatic Updater 9b367fcfe6 update copyright notice 2010-09-29 23:47:05 +00:00
Automatic Updater e01f44b37b newcopyrights 2010-09-29 23:30:44 +00:00
Automatic Updater 01311387fb auto update 2010-09-29 23:16:46 +00:00
Automatic Updater a431c67d58 update 2010-09-29 05:16:28 +00:00
Mark Andrews 34f010449c #include <isc/print.h> 2010-09-29 04:30:13 +00:00
Automatic Updater b2c7d2874a update 2010-09-29 04:18:27 +00:00
Mark Andrews 5e2f047a5e 2965. [func] Test HMAC functions using test data from RFC 2104 and
RFC 4634. [RT #21702]
2010-09-29 04:03:00 +00:00
Mark Andrews 2015023399 2965. [func] Test HMAC functions using test data from RFC 2104 and RFC 4634. [RT #21702] 2010-09-29 04:00:16 +00:00
Automatic Updater 560c6b3773 update 2010-09-24 09:16:21 +00:00
Automatic Updater 7041e86986 update copyright notice 2010-09-24 08:31:23 +00:00
Automatic Updater 9b1207058e newcopyrights 2010-09-24 08:28:07 +00:00
Automatic Updater fbe2a88bda update 2010-09-24 08:15:33 +00:00
Mark Andrews b2c8cc4f2d placeholder 2010-09-24 08:10:12 +00:00
Automatic Updater 246f9ea6d6 update 2010-09-24 05:15:42 +00:00
Mark Andrews ed83fa75f5 2963. [security] The allow-query acl was being applied instead of the
allow-query-cache acl to cache lookups. [RT #22114]
2010-09-24 05:09:03 +00:00
Automatic Updater 02f42ed1d9 update 2010-09-22 01:15:24 +00:00
Automatic Updater 3ce014e9af regen HEAD 2010-09-22 01:13:54 +00:00
Automatic Updater 7c267be4aa auto update 2010-09-21 23:16:16 +00:00
Automatic Updater 7d70c8c834 update 2010-09-21 20:15:31 +00:00
Paul Ebersman 3b9a5b7cdd fixed typo from man.dnysssec to man.dnssec.
reviewed by jreed, currently just fixed in HEAD.
2010-09-21 19:47:57 +00:00
Automatic Updater d738096795 update 2010-09-17 05:15:38 +00:00
Mark Andrews 9eba1cf5e5 spelling 2010-09-17 04:32:59 +00:00
Automatic Updater cf86dfbe47 update 2010-09-16 05:15:38 +00:00
Mark Andrews c470afc7ac 2962. [port] win32: add more dependancies to BINDBuild.dsw.
[RT #22062]
2010-09-16 04:56:06 +00:00
Automatic Updater c083414f34 update 2010-09-15 23:30:26 +00:00
Mark Andrews 165501a801 simplify grep 2010-09-15 23:22:02 +00:00
Automatic Updater f536c72a44 update 2010-09-15 16:15:36 +00:00
Evan Hunt cff5da57d6 The "resolver" test was failing on systems with old versions of "grep". 2010-09-15 15:45:07 +00:00
Automatic Updater 27d8bdc81f update 2010-09-15 12:50:57 +00:00
Automatic Updater 3255640981 update copyright notice 2010-09-15 12:38:36 +00:00
Automatic Updater 2cdbfcdad9 newcopyrights 2010-09-15 12:34:00 +00:00
Mark Andrews a6e1f63f50 ./bin/tests/system/resolver/ns4/named.noaa 2010-09-15 12:30:45 +00:00
Mark Andrews 506a2177bf 2961. [bug] Be still more selective about the non-authoritative
answers we apply change 2748 to. [RT #22074]
2010-09-15 12:21:27 +00:00
Automatic Updater f636b969f0 update 2010-09-15 12:15:34 +00:00
Mark Andrews 082f42dcf2 2960. [func] Check that named accepts non-authoritative answers.
[RT #21594]
2010-09-15 12:07:56 +00:00
Automatic Updater de6e3c1dc4 update 2010-09-15 04:16:34 +00:00
Mark Andrews c75523bcb3 2959. [func] Check that named starts with a missing masterfile.
[RT #22076]

2958.   [bug]           named failed to start with a missing master file.
                        [RT #22076]
2010-09-15 03:32:34 +00:00
Automatic Updater ca1b023107 update 2010-09-15 03:16:13 +00:00
Mark Andrews 70ba55161b 2957. [bug] entropy_get() and entropy_getpseudo() failed to match
the API for RAND_bytes() and RAND_pseudo_bytes()
                        respectively. [RT #21962]
2010-09-15 03:06:15 +00:00
Automatic Updater 2df9c63cad auto update 2010-09-14 23:16:31 +00:00
Automatic Updater 8e61f264fd update 2010-09-14 00:15:52 +00:00
Automatic Updater dc9fa0be37 update copyright notice 2010-09-13 23:46:58 +00:00
Automatic Updater ede7b1df75 newcopyrights 2010-09-13 23:30:39 +00:00
Automatic Updater 5970bec141 auto update 2010-09-13 23:16:34 +00:00
Automatic Updater 30c76ec787 update 2010-09-13 07:15:26 +00:00
Mark Andrews ad9107efaa 2956. [port] Enable atomic operations on the PowerPC64. [RT #21899] 2010-09-13 07:06:05 +00:00
Automatic Updater f56ced0b9d update 2010-09-13 04:16:04 +00:00
Mark Andrews 3f9f14055b 2955. [func] Provide more detail in the recursing log. [RT #22043] 2010-09-13 03:37:43 +00:00
Mark Andrews 75f48cecb3 2954. [bug] contrib: dlz_mysql_driver.c bad error handling on
build_sqldbinstance failure. [RT #21623]
2010-09-13 03:27:48 +00:00
Automatic Updater 8c13f838f5 auto update 2010-09-10 23:16:31 +00:00
Automatic Updater b73d90b60b auto update 2010-09-09 23:16:34 +00:00
Automatic Updater bbc604018c update 2010-09-08 00:16:23 +00:00
Automatic Updater 7306e8e4ee update copyright notice 2010-09-07 23:46:59 +00:00
Automatic Updater e171a4137c newcopyrights 2010-09-07 23:30:44 +00:00
Automatic Updater 1e6b56b088 update 2010-09-07 03:16:18 +00:00
Mark Andrews 8fb412590e 2953. [bug] Silence spurious "expected covering NSEC3, got an
exact match" message when returning a wildcard
                        no data response. [RT #21744]
2010-09-07 02:28:17 +00:00
Automatic Updater 8bf7aca489 update 2010-09-07 02:15:58 +00:00
Mark Andrews 1b42401954 2952. [port] win32: named-checkzone and named-checkconf failed
to initialise winsock. [RT #21932]
2010-09-07 01:49:08 +00:00
Automatic Updater ce9ba78d11 update 2010-09-07 01:15:33 +00:00
Mark Andrews 240a7dc59d 2951. [bug] named failed to generate a correct signed response
in a optout, delegation only zone with no secure
                        delegations. [RT #22007]
2010-09-07 00:58:36 +00:00
Automatic Updater e92e62990b auto update 2010-09-06 23:16:32 +00:00
Automatic Updater b8bb4e6e94 update 2010-09-06 05:15:44 +00:00
Mark Andrews e588bfe689 2950. [bug] named failed to perform a SOA up to date check when
falling back to TCP on UDP timeouts when
                        ixfr-from-differences was set. [RT #21595]
2010-09-06 04:41:13 +00:00
Mark Andrews 02a211f4c4 2949. [bug] dns_view_setnewzones() contained a memory leak if
it was called multiple times. [RT #21942]
2010-09-06 04:31:11 +00:00
Automatic Updater 3045036e49 update 2010-09-05 12:15:17 +00:00
Francis Dupont ec288f1a26 reindent 2010-09-05 12:14:26 +00:00
Automatic Updater c2c67d6e47 auto update 2010-09-02 23:16:27 +00:00
Automatic Updater e928ad8bf9 auto update 2010-08-31 23:16:31 +00:00
Automatic Updater 196f1cf015 auto update 2010-08-27 23:16:28 +00:00
Automatic Updater d851310950 update 2010-08-26 00:16:01 +00:00
Automatic Updater dac2623103 update copyright notice 2010-08-25 23:46:37 +00:00
Automatic Updater ff69107b38 newcopyrights 2010-08-25 23:30:53 +00:00
Automatic Updater 5c7f849c70 update 2010-08-25 06:15:21 +00:00
Mark Andrews fd8fb4df84 bin/tests/system/org.isc.bind.system.plist 2010-08-25 05:33:56 +00:00
Automatic Updater ad901e21c0 update 2010-08-25 05:15:18 +00:00
Mark Andrews 17be07ab81 2948. [port] MacOS: provide a mechanism to configure the test
interfaces at reboot. See bin/tests/system/README
                        for details.
2010-08-25 04:51:51 +00:00
Automatic Updater 5fdcf9e935 update 2010-08-25 01:15:27 +00:00
Mark Andrews 0b57424d28 update 2010-08-25 01:09:53 +00:00
Automatic Updater b7c24d4b8e update 2010-08-24 06:15:22 +00:00
Mark Andrews 684a4498ba cleanup 2010-08-24 05:27:37 +00:00
Automatic Updater 0a1bc4e536 update 2010-08-24 01:15:20 +00:00
Mark Andrews b5fd149e7e silence signed/unsigned warning hpux 2010-08-24 01:00:31 +00:00
Automatic Updater 512d7c315f update 2010-08-23 23:15:49 +00:00
Tatuya JINMEI 神明達哉 708b78f157 placeholder for 9.7.1-P2-DENIC (RT #21886) 2010-08-23 23:08:52 +00:00
Automatic Updater 4cb4d7a110 update 2010-08-21 01:15:17 +00:00
Automatic Updater fde6bfde6e regen HEAD 2010-08-21 01:14:00 +00:00
Automatic Updater a3cd596c87 update 2010-08-20 02:15:26 +00:00
Mark Andrews 20599f3d0e 2946. [doc] Document the default values for the minimum and maximum zone refresh and retry values in the ARM. [RT #21886] 2010-08-20 01:31:10 +00:00
Automatic Updater 3a52f3444d update 2010-08-20 01:15:31 +00:00
Automatic Updater c25877b363 regen HEAD 2010-08-20 01:14:19 +00:00
Automatic Updater 6010e5d622 update 2010-08-20 00:16:02 +00:00
Mark Andrews 38abdbf816 2945. [doc] Update empty-zones list in ARM. [RT #21772]
2944.   [maint]         Remove ORCHID prefix from built in empty zones.
                        [RT #21772]
2010-08-20 00:13:26 +00:00
Automatic Updater ff61017de2 update 2010-08-18 00:16:06 +00:00
Automatic Updater 7202b5cf66 update copyright notice 2010-08-17 23:46:46 +00:00
Automatic Updater 255571ad34 newcopyrights 2010-08-17 23:30:46 +00:00
Automatic Updater 0aeba1af0d update 2010-08-17 04:16:10 +00:00
Mark Andrews e0c50ca36a update default id range to match that used (1..7) 2010-08-17 04:08:57 +00:00
Automatic Updater e8c1bd086f update 2010-08-17 02:15:21 +00:00
Automatic Updater 3acf5eb97c regen HEAD 2010-08-17 01:15:38 +00:00
Automatic Updater 56876f1e68 update 2010-08-17 00:15:48 +00:00
Automatic Updater f428e385a4 update copyright notice 2010-08-16 23:46:52 +00:00
Automatic Updater e23256e740 newcopyrights 2010-08-16 23:30:42 +00:00
Automatic Updater 8661637b9d auto update 2010-08-16 23:16:35 +00:00
Automatic Updater 2a9a0f406b update 2010-08-16 23:15:26 +00:00
Mark Andrews 10f9e687f5 silence redefinition warnings MacOS 2010-08-16 22:41:16 +00:00
Mark Andrews c6f4972c74 2943. [func] Add support to load new keys into managed zones
without signing immediately with "rndc loadkeys".
                        Add support to link keys with "dnssec-keygen -S"
                        and "dnssec-settime -S".  [RT #21351]
2010-08-16 22:21:07 +00:00
Automatic Updater 6ee897e2b3 update 2010-08-16 06:15:25 +00:00
Mark Andrews f94ec08c17 2942. [contrib] zone2sqlite failed to setup the entropy sources.
[RT #21610]
2010-08-16 05:32:44 +00:00
Automatic Updater f0b944480e update 2010-08-16 05:15:24 +00:00
Mark Andrews 8bc194b266 2941. [bug] sdb and sdlz (dlz's zone database) failed to support
DNAME at the zone apex.  [RT #21610]
2010-08-16 04:49:14 +00:00
Automatic Updater 8171f2c3dd update 2010-08-14 00:15:51 +00:00
Automatic Updater 2b43d1d8c5 update copyright notice 2010-08-13 23:47:04 +00:00
Automatic Updater 665ba746c0 newcopyrights 2010-08-13 23:30:56 +00:00
Automatic Updater 6deb576114 auto update 2010-08-13 23:16:31 +00:00
Automatic Updater 30036552e4 update 2010-08-13 15:15:21 +00:00
Francis Dupont 7641867b4c fix win32 build 2010-08-13 14:33:31 +00:00
Automatic Updater 20dc3ddcd4 update 2010-08-13 11:15:20 +00:00
Francis Dupont 0395219694 remove connection aborted error message [#21549] 2010-08-13 10:49:58 +00:00
Francis Dupont bcb444aed0 remove connection aborted error message 2010-08-13 10:45:32 +00:00
Automatic Updater bdc3114b56 update 2010-08-13 08:15:23 +00:00
Mark Andrews 7c681d0750 2939. [func] Check that named successfully skips NSEC3 records
that fail to match the NSEC3PARAM record currently
                        in use. [RT# 21868]
2010-08-13 07:32:42 +00:00
Mark Andrews da45cdaf79 placeholder 2010-08-13 07:26:50 +00:00
Automatic Updater c115a50963 update 2010-08-13 07:15:20 +00:00
Mark Andrews c73d8c1b72 2938. [bug] When skipping NSEC3 records that don't match the
current NSEC3PARAM record in use for zone named
                        could dereference a uninitialised pointer attempting
                        to obtain a lock. [RT# 21868]
2010-08-13 06:46:25 +00:00
Automatic Updater ef0d20244d update 2010-08-13 04:15:32 +00:00
Mark Andrews e8c17c7453 ./bin/tests/system/addzone/ns2/default.nzf.in 2010-08-13 03:35:38 +00:00
Automatic Updater 0d5a43e21a update 2010-08-13 00:15:59 +00:00
Automatic Updater 87be41dc7b update 2010-08-12 22:15:20 +00:00
Tatuya JINMEI 神明達哉 d0b75b9ff6 define the wrapper function for mem_isovermem().
(a regression in rt21818)
2010-08-12 21:30:26 +00:00
Automatic Updater 1d41be16c7 update 2010-08-12 10:15:20 +00:00
Francis Dupont bf22bad528 removing unused 2010-08-12 09:52:35 +00:00
Francis Dupont 13f0ecd037 re-indent 2010-08-12 09:31:50 +00:00
Automatic Updater d1fa703c08 update 2010-08-12 04:15:32 +00:00
Evan Hunt 9b7efe7aca Removed a leftover UNUSED statement referencing a parameter that doesn't
exist anymore.
2010-08-12 04:04:14 +00:00
Automatic Updater e52171437f update 2010-08-12 03:15:44 +00:00
Mark Andrews 020b3b1379 new draft 2010-08-12 02:30:25 +00:00
Automatic Updater 75f004c92b update 2010-08-12 02:15:21 +00:00
Mark Andrews bde46569f3 .orig -> .in as .orig is used by patch 2010-08-12 01:31:36 +00:00
Automatic Updater 0a93c74a35 update 2010-08-12 01:15:17 +00:00
Automatic Updater 82d13321f4 regen HEAD 2010-08-12 01:14:30 +00:00
Automatic Updater 0e3b06fb84 update 2010-08-12 00:15:59 +00:00
Automatic Updater cc4dd0d08d update copyright notice 2010-08-11 23:46:42 +00:00
Automatic Updater 30e7870023 update 2010-08-11 23:15:34 +00:00
Tatuya JINMEI 神明達哉 253ae50e09 required ctx is valid in mem_isovermem(). 2010-08-11 23:11:45 +00:00
Tatuya JINMEI 神明達哉 27fe1966c9 2937. [bug] Worked around an apparent race condition in over
memory conditions.  Without this fix a DNS cache DB or
			ADB could incorrectly stay in an over memory state,
			effectively refusing further caching, which
			subsequently made a BIND 9 caching server unworkable.
			This fix prevents this problem from happening by
			polling the state of the memory context, rather than
			making a copy of the state, which appeared to cause
			a race.  This is a "workaround" in that it doesn't
			solve the possible race per se, but several experiments
			proved this change solves the symptom.  Also, the
			polling overhead hasn't been reported to be an issue.
			This bug should only affect a caching server that
			specifies a finite max-cache-size.  It's also quite
			likely that the bug happens only when enabling threads,
			but it's not confirmed yet. [RT #21818]
2010-08-11 22:54:58 +00:00
Automatic Updater fc7bf6dcad update 2010-08-11 18:15:22 +00:00
Evan Hunt cfd262045c 2936. [func] Improved configuration syntax and multiple-view
support for addzone/delzone feature (see change
			#2930).  Removed "new-zone-file" option, replaced
			with "allow-new-zones (yes|no)".  The new-zone-file
			for each view is now created automatically, with
			a filename generated from a hash of the view name.
			It is no longer necessary to "include" the
			new-zone-file in named.conf; this happens
			automatically.  Zones that were not added via
			"rndc addzone" can no longer be removed with
			"rndc delzone". [RT #19447]
2010-08-11 18:14:20 +00:00
Automatic Updater 7d7cdecee6 update 2010-08-11 13:15:16 +00:00
Francis Dupont 26f55cbdf6 trivial fix in comment 2010-08-11 12:37:36 +00:00
Automatic Updater d8ba58b392 update 2010-08-11 01:15:31 +00:00
Mark Andrews 999ffe78c4 new draft 2010-08-11 00:58:20 +00:00
Automatic Updater 2fa731eafb update 2010-08-11 00:16:06 +00:00
Automatic Updater 548317f929 update copyright notice 2010-08-10 23:48:19 +00:00
Automatic Updater 93bd88e172 newcopyrights 2010-08-10 23:30:37 +00:00
Automatic Updater b5ef90b267 auto update 2010-08-10 23:16:25 +00:00
Automatic Updater 9a55ac6af1 update 2010-08-10 10:15:26 +00:00
Mark Andrews 4b6cb8d09e 2935. [bug] nsupdate: improve 'file not found' error message.
[RT #21871]
2010-08-10 09:51:47 +00:00
Mark Andrews 712b976a06 2934. [bug] Use ANSI C compliant shift range in lib/isc/entropy.c. [RT #21871] 2010-08-10 09:32:06 +00:00
Automatic Updater c567a85061 update 2010-08-10 09:15:24 +00:00
Mark Andrews f083530138 2933. [bug] 'dig +nsid' used stack memory after it went out of
scope.  This could potentially result in a unknown,
                        potentially malformed, EDNS option being sent instead
                        of the desired NSID option. [RT #21781]
2010-08-10 08:39:15 +00:00
Automatic Updater 2d9248490c auto update 2010-08-09 23:16:32 +00:00
Automatic Updater 577582dd68 update 2010-08-09 23:15:30 +00:00
Evan Hunt cb933b69ff 2932. [cleanup] Corrected a numbering error in the "dnssec" test.
[RT #21597]
2010-08-09 22:34:56 +00:00
Automatic Updater 8e9eb313e7 auto update 2010-08-05 23:16:30 +00:00
Automatic Updater efee6b51c7 update 2010-08-04 00:16:01 +00:00
Automatic Updater 8ac1f6a48c update copyright notice 2010-08-03 23:46:39 +00:00
Automatic Updater be63e68c51 newcopyrights 2010-08-03 23:30:45 +00:00
Automatic Updater b8848eded7 update 2010-08-03 17:15:29 +00:00
Tatuya JINMEI 神明達哉 dbae1499ba added me to authors. approved by Evan. 2010-08-03 16:40:45 +00:00
Automatic Updater 26d137dd7d update 2010-07-20 05:15:21 +00:00
Mark Andrews 7b830cb17f while (1) -> for (;;) to silence compiler warning 2010-07-20 04:52:21 +00:00
Mark Andrews 0ddcd0c0ce format/arg mismatch solaris 2010-07-20 04:46:49 +00:00
Automatic Updater 168903d09b update 2010-07-19 06:15:19 +00:00
Mark Andrews 7a8d1e1e2e 0 -> 0U 2010-07-19 06:13:28 +00:00
Automatic Updater a7a94ab93a update 2010-07-19 04:15:24 +00:00
Mark Andrews dfbda37366 silence compiler warnings about (char) as index to array 2010-07-19 04:13:38 +00:00
Automatic Updater 06573b9f35 auto update 2010-07-16 23:16:21 +00:00
Automatic Updater c48e03b9a3 update 2010-07-15 02:15:23 +00:00
Tatuya JINMEI 神明達哉 f1f39b7e07 2931. [bug] Temporarily and partially disable change 2864
because it would cause inifinite attempts of RRSIG
			queries.  This is an urgent care fix; we'll
			revisit the issue and complete the fix later.
			[RT #21710]
2010-07-15 01:17:45 +00:00
Automatic Updater 1c3359e8f7 auto update 2010-07-14 23:16:22 +00:00
Automatic Updater 7759bb4896 update 2010-07-12 04:15:21 +00:00
Mark Andrews b24b6ddab7 5933: Use of GOST Signature Algorithms in DNSKEY
and RRSIG Resource Records for DNSSEC
2010-07-12 03:17:37 +00:00
Automatic Updater 3101b7bd21 update 2010-07-12 01:15:17 +00:00
Automatic Updater 5d9e1d7500 regen HEAD 2010-07-12 01:14:20 +00:00
Automatic Updater c7578930ec update 2010-07-12 00:15:57 +00:00
Automatic Updater a90aca78aa update copyright notice 2010-07-11 23:46:54 +00:00
Automatic Updater e5fe07a7eb newcopyrights 2010-07-11 23:30:36 +00:00
Automatic Updater 239df719b0 update 2010-07-11 06:15:19 +00:00
Evan Hunt a207cfc5d1 Removed a duplicate entry in namedconf.c. 2010-07-11 05:44:15 +00:00
Automatic Updater 99ab3cfce2 update 2010-07-11 02:15:23 +00:00
Evan Hunt 5312c2ffbe dnssec and dlv tests included master zones whose master files were missing.
this was a bug that hadn't been noticed before, but 19447 added a test for
that condition and it caused test failures.
2010-07-11 01:18:24 +00:00
Automatic Updater 816e5bac7d update 2010-07-11 01:15:20 +00:00
Automatic Updater ae80331be3 regen HEAD 2010-07-11 01:14:16 +00:00
Automatic Updater 0733592092 update 2010-07-11 00:15:54 +00:00
Evan Hunt 86dcc40058 2930. [experimental] New "rndc addzone" and "rndc delzone" commads
allow dynamic addition and deletion of zones.
			To enable this feature, specify a "new-zone-file"
			option at the view or options level in named.conf.
			Zone configuration information for the new zones
			will be written into that file.  To make the new
			zones persist after a restart, "include" the file
			into named.conf in the appropriate view.  (Note:
			This feature is not yet documented, and its syntax
			is expected to change.) [RT #19447]
2010-07-11 00:12:57 +00:00
Automatic Updater 773896a200 update 2010-07-10 01:15:17 +00:00
Automatic Updater 7c6b9b2638 regen HEAD 2010-07-10 01:14:20 +00:00
Automatic Updater 2a69cdc964 update 2010-07-10 00:16:01 +00:00
Automatic Updater 1b892cf691 update copyright notice 2010-07-09 23:46:51 +00:00
Automatic Updater 7858b0168b newcopyrights 2010-07-09 23:33:38 +00:00
Automatic Updater df23bca11a update 2010-07-09 05:15:54 +00:00
Evan Hunt bf9b852c3e 2929. [bug] Improved handling of GSS security contexts:
- added LRU expiration for generated TSIGs
			 - added the ability to use a non-default realm
                         - added new "realm" keyword in nsupdate
			 - limited lifetime of generated keys to 1 hour
			   or the lifetime of the context (whichever is
			   smaller)
			[RT #19737]
2010-07-09 05:13:15 +00:00
Automatic Updater 385c6ae102 auto update 2010-07-07 23:16:25 +00:00
Automatic Updater 0ec2958f5e update 2010-07-07 08:15:17 +00:00
Mark Andrews 7738656b90 new draft 2010-07-07 08:05:29 +00:00
Automatic Updater c964b0b9bd update 2010-07-04 01:15:22 +00:00
Mark Andrews 922e80affe new draft 2010-07-04 01:13:13 +00:00
Mark Andrews ff5864ef42 2928. [bug] Be more selective about the non-authoritative
answer we apply change 2748 to. [RT #21594]
2010-07-04 00:48:57 +00:00
Automatic Updater 86532a6230 auto update 2010-07-02 23:16:22 +00:00
Automatic Updater 60ddb8f01e update 2010-07-02 00:15:43 +00:00
Automatic Updater 817ae21947 newcopyrights 2010-07-01 23:30:35 +00:00
Automatic Updater 51ad8ab5e5 auto update 2010-07-01 23:16:19 +00:00
Tatuya JINMEI 神明達哉 4c517d66b5 canceled previous commit (wrong branch) 2010-07-01 19:26:08 +00:00
Tatuya JINMEI 神明達哉 cd98628ca6 regen 2010-07-01 19:19:27 +00:00
Automatic Updater 27c982c86d update 2010-07-01 18:15:22 +00:00
Tatuya JINMEI 神明達哉 f3792d4bda placeholdr for RT #21474 2010-07-01 17:36:09 +00:00
Automatic Updater 80114610e4 auto update 2010-06-29 23:16:20 +00:00
Automatic Updater 11d742eaba update 2010-06-29 23:15:21 +00:00
Mark Andrews 9ad05226e8 new draft 2010-06-29 23:09:13 +00:00
Automatic Updater 0b45829b11 update 2010-06-29 03:15:58 +00:00
Mark Andrews 45d9b38097 placeholder 2010-06-29 02:51:13 +00:00
Automatic Updater 20c9d11bab update 2010-06-29 00:15:56 +00:00
Automatic Updater b2f875a535 update copyright notice 2010-06-28 23:46:44 +00:00
Automatic Updater 96249c843a newcopyrights 2010-06-28 23:30:41 +00:00
Automatic Updater d045e9694c auto update 2010-06-28 23:16:23 +00:00
Automatic Updater e7fb023fd0 update 2010-06-28 04:15:44 +00:00
Mark Andrews ea72c1dff0 new draft 2010-06-28 03:43:05 +00:00
Automatic Updater 3a3dba4431 update 2010-06-28 02:15:24 +00:00
Mark Andrews a7d2b922ee match the dig.out.ns#.$n to the nameserver 2010-06-28 01:34:11 +00:00
Mark Andrews 8fa6ca58b6 check that we have non-cachable answers to test against 2010-06-28 01:31:49 +00:00
Automatic Updater 2bd0d8b03f update 2010-06-28 00:16:02 +00:00
Mark Andrews 9408328f1d handle very short source files 2010-06-27 23:42:22 +00:00
Automatic Updater 56a67f949b update 2010-06-27 00:15:50 +00:00
Automatic Updater 1b67d9b719 update copyright notice 2010-06-26 23:46:49 +00:00
Automatic Updater e628576d3b newcopyrights 2010-06-26 23:30:44 +00:00
Automatic Updater 57606549c0 update 2010-06-26 06:15:21 +00:00
Mark Andrews 2cf74a72fd isc_boolean_t -> dns_v4_aaaa_t 2010-06-26 05:30:30 +00:00
Automatic Updater cc455423fd update 2010-06-26 03:16:03 +00:00
Mark Andrews f8a9a38ee4 bin/tests/system/dnssec/ns7/named.nosoa 2010-06-26 02:19:32 +00:00
Automatic Updater 370c8e69a1 update 2010-06-26 01:15:26 +00:00
Automatic Updater 1238b38c9f regen HEAD 2010-06-26 01:14:19 +00:00
Mark Andrews 73134bd1c7 add /* NOT DOCUMENTED */ 2010-06-26 00:20:33 +00:00
Automatic Updater 05b821a31a update 2010-06-26 00:16:02 +00:00
Mark Andrews 810656a187 2925. [bug] Named failed to accept uncachable negative responses
from insecure zones. [RT# 21555]
2010-06-25 23:50:13 +00:00
Automatic Updater cf309ffeee update copyright notice 2010-06-25 23:46:51 +00:00
Automatic Updater f4029eb746 newcopyrights 2010-06-25 23:30:34 +00:00
Automatic Updater 08b233c101 auto update 2010-06-25 23:16:18 +00:00
Automatic Updater e7c1818c2c update 2010-06-25 07:30:49 +00:00
Mark Andrews f35a87f58f remove leading zeros on keyid
account for trusted keys not applying to _bind anymore
2010-06-25 07:28:46 +00:00
Automatic Updater 49887c2aa7 update 2010-06-25 04:15:32 +00:00
Mark Andrews bf13e709db 2924. [func] 'rndc secroots' dump a combined summary of the
current managed keys combined with trusted keys.
                        [RT #20904]
2010-06-25 03:24:05 +00:00
Automatic Updater 256b56f440 update 2010-06-24 08:15:31 +00:00
Mark Andrews bdc1d1b1bf changes number 2010-06-24 07:34:41 +00:00
Mark Andrews 43888c2315 2922. [bug] 'dig +trace' could drop core after "connection
timeout". [RT #21514]
2010-06-24 07:22:18 +00:00
Automatic Updater 9f1e86e4ef update 2010-06-24 00:15:55 +00:00
Automatic Updater b8d4e96e95 update copyright notice 2010-06-23 23:46:58 +00:00
Automatic Updater 782b50b4eb newcopyrights 2010-06-23 23:30:33 +00:00
Automatic Updater 1227b00357 auto update 2010-06-23 23:16:24 +00:00
Automatic Updater d7e4ff21da update 2010-06-23 04:15:54 +00:00
Mark Andrews 0627874ff8 s/to soon/too soon/ 2010-06-23 03:31:17 +00:00
Mark Andrews b7ba273d32 add period 2010-06-23 03:29:11 +00:00
Automatic Updater 96118efd9a update 2010-06-23 03:15:53 +00:00
Mark Andrews c52235e52e 2922 [contrib] Update zkt to version 1.0.: 2010-06-23 02:42:10 +00:00
Automatic Updater 0123677dc3 update 2010-06-23 02:15:34 +00:00
Mark Andrews 4a8dc5f8ef 2921. [bug] The resolver could attempt to destroy a fetch context
to soon.  [RT #19878]
2010-06-23 01:31:43 +00:00
Automatic Updater 945b6a3ae4 update 2010-06-23 01:15:17 +00:00
Automatic Updater 07ee99c7d0 regen HEAD 2010-06-23 01:14:18 +00:00
Automatic Updater 4a7d0ef87c update 2010-06-23 00:15:46 +00:00
Automatic Updater b61690dbad update copyright notice 2010-06-22 23:46:52 +00:00
Mark Andrews 8c9c79e5fe regen 2010-06-22 23:34:57 +00:00
Automatic Updater 3899610326 auto update 2010-06-22 23:16:15 +00:00
Automatic Updater d138a6bfe3 update 2010-06-22 07:15:27 +00:00
Mark Andrews c5ff97f471 2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients.  New acl 'filter-aaaa' (default any).
2010-06-22 06:16:34 +00:00
Automatic Updater 25c92b85f0 update 2010-06-22 06:15:17 +00:00
Mark Andrews 511995ed11 reverse accidental commit 2010-06-22 06:14:20 +00:00
Automatic Updater 713cd334b6 update 2010-06-22 04:15:31 +00:00
Mark Andrews 48dfee7150 2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients.  New acl 'filter-aaaa' (default any).
2010-06-22 04:03:38 +00:00
Automatic Updater 86d12575ff update 2010-06-22 00:15:57 +00:00
Automatic Updater c7c7ba3977 update copyright notice 2010-06-21 23:46:48 +00:00
Automatic Updater c07cdac6cf newcopyrights 2010-06-21 23:30:36 +00:00
Automatic Updater cc2adcaa10 regen 2010-06-21 23:30:33 +00:00
Automatic Updater 8d1ee9c8db update 2010-06-21 03:15:58 +00:00
Mark Andrews 718c4becc5 2919. [func] Add autosign-ksk and autosign-zsk virtual time tests.
[RT #20840]
2010-06-21 02:31:46 +00:00
Automatic Updater 8bb6a55bb5 update 2010-06-21 00:16:03 +00:00
Automatic Updater 673ed6391e update copyright notice 2010-06-20 23:46:45 +00:00
Automatic Updater 27794bebe2 newcopyrights 2010-06-20 23:30:41 +00:00
Automatic Updater d5289b74fe regen 2010-06-20 23:30:40 +00:00
Automatic Updater 32064fc67f update 2010-06-20 08:15:55 +00:00
Mark Andrews be28cc55c5 regen 2010-06-20 07:19:18 +00:00
Mark Andrews ea7760e72a report bind.keys and bindkeys.pl versions in output 2010-06-20 07:18:30 +00:00
Mark Andrews 56b9fb463c add bind.keys.h dependancy on ${srcdir}/bindkeys.pl 2010-06-20 07:17:02 +00:00
Mark Andrews 1154295949 cvs version identifier 2010-06-20 07:15:28 +00:00
Automatic Updater 0d57f20843 update 2010-06-19 01:15:19 +00:00
Mark Andrews 4ccc69f808 new draft 2010-06-19 00:39:55 +00:00
Automatic Updater 6f4608e30c update 2010-06-19 00:15:55 +00:00
Automatic Updater efa460418c update copyright notice 2010-06-18 23:46:43 +00:00
Automatic Updater 7c899ff8af newcopyrights 2010-06-18 23:30:39 +00:00
Automatic Updater 35dffd7e21 update 2010-06-18 05:39:24 +00:00
Mark Andrews ae538374fe AAAA not A 2010-06-18 05:36:24 +00:00
Automatic Updater 3b4e78c7df update 2010-06-18 03:16:33 +00:00
Mark Andrews de73ef7ecd /bin/tests/virtual-time/common/controls.conf 2010-06-18 02:48:28 +00:00
Mark Andrews 17198e77b8 ./bin/tests/virtual-time/README 2010-06-18 02:45:30 +00:00
Automatic Updater e05203a2ff update 2010-06-18 02:15:31 +00:00
Mark Andrews 081b36ff95 2918. [maint] Add AAAA address for I.ROOT-SERVERS.NET. 2010-06-18 02:11:44 +00:00
Mark Andrews 4b0355d885 9.8.0a1 2010-06-18 02:05:02 +00:00
Automatic Updater e1527490c1 update 2010-06-18 00:15:58 +00:00
Automatic Updater 0062141398 auto update 2010-06-17 23:16:27 +00:00
Automatic Updater e4f2caddfa update 2010-06-17 06:15:23 +00:00
Mark Andrews 43c770b998 2917. [func] Virtual time test framework. [RT #20801] 2010-06-17 05:39:19 +00:00
Automatic Updater 0c175b2bc8 update 2010-06-17 00:15:41 +00:00
Mark Andrews afa4e998ed custom_YAHOO_v9_7_1 2010-06-16 23:50:01 +00:00
Automatic Updater 9c208977a1 auto update 2010-06-15 23:16:21 +00:00
Automatic Updater 14f17e6406 update 2010-06-15 15:15:16 +00:00
Mark Andrews 9565427120 new draft 2010-06-15 14:20:40 +00:00
Automatic Updater fcd9888d1e update 2010-06-12 00:16:00 +00:00
Automatic Updater 263874836b update copyright notice 2010-06-11 23:46:49 +00:00
Automatic Updater 06795359e2 newcopyrights 2010-06-11 23:30:43 +00:00
Automatic Updater 74f4de925d update 2010-06-11 02:15:48 +00:00
Mark Andrews 96fae19c97 restore export of PERL PK11GEN PK11LIST PK11DEL 2010-06-11 01:57:36 +00:00
Automatic Updater 7cad85e750 update 2010-06-11 00:49:48 +00:00
Automatic Updater d1de56d808 update 2010-06-10 07:17:42 +00:00
36 changed files with 667 additions and 708 deletions
+5
View File
@@ -0,0 +1,5 @@
Content-Type: application/X-atf-atffile; version="1"
prop: test-suite = bind9
tp: lib
+24
View File
@@ -1,3 +1,27 @@
--- 9.7.3-P3 released ---
3124. [bug] Use an rdataset attribute flag to indicate
negative-cache records rather than using rrtype 0;
this will prevent problems when that rrtype is
used in actual DNS packets. [RT #24777]
--- 9.7.3-P2 released (withdrawn) ---
3123. [security] Change #2912 exposed a latent flaw in
dns_rdataset_totext() that could cause named to
crash with an assertion failure. [RT #24777]
--- 9.7.3-P1 released ---
3121. [security] An authoritative name server sending a negative
response containing a very large RRset could
trigger an off-by-one error in the ncache code
and crash named. [RT #24650]
3120. [bug] Named could fail to validate zones listed in a DLV
that validated insecure without using DLV and had
DS records in the parent zone. [RT #24631]
--- 9.7.3 released ---
3018. [bug] Named failed to check for the "none;" acl when deciding
-318
View File
@@ -1,318 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title></title><link rel="stylesheet" href="release-notes.css" type="text/css" /><meta name="generator" content="DocBook XSL Stylesheets V1.75.2" /></head><body><div class="article"><div class="titlepage"><hr /></div>
<div class="section" title="Introduction"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id2549151"></a>Introduction</h2></div></div></div>
<p>
BIND 9.7.3 is the current release of BIND 9.7.
</p>
<p>
This document summarizes changes from BIND 9.7.1 to BIND 9.7.3.
Please see the CHANGES file in the source code release for a
complete list of all changes.
</p>
</div>
<div class="section" title="Download"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415638"></a>Download</h2></div></div></div>
<p>
The latest development version of BIND 9 software can always be found
on our web site at
<a class="ulink" href="http://www.isc.org/downloads/development" target="_top">http://www.isc.org/downloads/development</a>.
There you will find additional information about each release,
source code, and some pre-compiled versions for certain operating
systems.
</p>
</div>
<div class="section" title="Support"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415690"></a>Support</h2></div></div></div>
<p>Product support information is available on
<a class="ulink" href="http://www.isc.org/services/support" target="_top">http://www.isc.org/services/support</a>
for paid support options. Free support is provided by our user
community via a mailing list. Information on all public email
lists is available at
<a class="ulink" href="https://lists.isc.org/mailman/listinfo" target="_top">https://lists.isc.org/mailman/listinfo</a>.
</p>
</div>
<div class="section" title="New Features"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415627"></a>New Features</h2></div></div></div>
<div class="section" title="9.7.2"><div class="titlepage"><div><div><h3 class="title"><a id="id3415698"></a>9.7.2</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
Zones may be dynamically added and removed with the
“rndc addzone” and “rndc delzone” commands. These
dynamically added zones are written to a per-view
configuration file. Do not rely on the configuration
file name nor contents as this will change in a future
release. This is an experimental feature at this time.
</li><li class="listitem">
Added new “filter-aaaa-on-v4” access control list to
select which IPv4 clients have AAAA record filtering
applied.
</li><li class="listitem">
A new command “rndc secroots” was added to dump a combined
summary of the currently managed keys combined with statically
configured trust anchors.
</li><li class="listitem">
Added support to load new keys into managed zones without
signing immediately with "rndc loadkeys". Added support
to link keys with "dnssec-keygen -S" and
"dnssec-settime -S".
</li></ul></div>
</div>
</div>
<div class="section" title="Feature Changes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415770"></a>Feature Changes</h2></div></div></div>
<div class="section" title="9.7.2"><div class="titlepage"><div><div><h3 class="title"><a id="id3415775"></a>9.7.2</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
Documentation improvements
</li><li class="listitem">
ORCHID prefixes were removed from the automatic empty
zone list.
</li><li class="listitem">
Improved handling of GSSAPI security contexts. Specifically,
better memory management of cached contexts, limited lifetime
of a context to 1 hour, and added a “realm” command to
nsupdate to allow selection of a non-default realm name.
</li><li class="listitem">
The contributed tool “zkt” was updated to version 1.0.
</li></ul></div>
</div>
</div>
<div class="section" title="Security Fixes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415805"></a>Security Fixes</h2></div></div></div>
<div class="section" title="9.7.2-P3"><div class="titlepage"><div><div><h3 class="title"><a id="id3415810"></a>9.7.2-P3</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
Adding a NO DATA signed negative response to cache failed to clear
any matching RRSIG records already in cache. A subsequent lookup
of the cached NO DATA entry could crash named (INSIST) when the
unexpected RRSIG was also returned with the NO DATA cache entry.
[RT #22288] [CVE-2010-3613] [VU#706148]
</li><li class="listitem">
BIND, acting as a DNSSEC validator, was determining if the NS RRset
is insecure based on a value that could mean either that the RRset
is actually insecure or that there wasn't a matching key for the RRSIG
in the DNSKEY RRset when resuming from validating the DNSKEY RRset.
This can happen when in the middle of a DNSKEY algorithm rollover,
when two different algorithms were used to sign a zone but only the
new set of keys are in the zone DNSKEY RRset.
[RT #22309] [CVE-2010-3614] [VU#837744]
</li><li class="listitem">
<p>
When BIND is running as an authoritative server for a zone and
receives a query for that zone data, it first checks for allow-query
acls in the zone statement, then in that view, then in global
options. If none of these exist, it defaults to allowing any query
(allow-query {"any"};).
</p>
<p>
With this bug, if the allow-query is not set in the zone statement,
it failed to check in view or global options and fell back to the
default of allowing any query. This means that queries that the zone
owner did not wish to allow were incorrectly allowed.
[RT #22418] [CVE-2010-3615] [VU#510208]
</p>
</li></ul></div>
</div>
<div class="section" title="9.7.2-P2"><div class="titlepage"><div><div><h3 class="title"><a id="id3415862"></a>9.7.2-P2</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
A flaw where the wrong ACL was applied was fixed. This flaw
allowed access to a cache via recursion even though the ACL
disallowed it.
</li></ul></div>
</div>
<div class="section" title="9.7.2-P1"><div class="titlepage"><div><div><h3 class="title"><a id="id3415878"></a>9.7.2-P1</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
If BIND, acting as a DNSSEC validating server, has two or more trust
anchors configured in named.conf for the same zone (such as
example.com) and the response for a record in that zone from the
authoritative server includes a bad signature, the validating server
will crash while trying to validate that query.
</li></ul></div>
</div>
</div>
<div class="section" title="Bug Fixes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3415898"></a>Bug Fixes</h2></div></div></div>
<div class="section" title="9.7.3"><div class="titlepage"><div><div><h3 class="title"><a id="id3415904"></a>9.7.3</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
BIND now builds with threads disabled in versions of NetBSD earlier
than 5.0 and with pthreads enabled by default in NetBSD versions 5.0
and higher. Also removes support for unproven-pthreads, mit-pthreads
and ptl2. [RT #19203]
</li><li class="listitem">
Added a regression test for fix 2896/RT #21045 ("rndc sign" failed
to properly update the zone when adding a DNSKEY for publication
only). [RT #21324]
</li><li class="listitem">
"nsupdate -l" now gives error message if "session.key" file is not
found. [RT #21670]
</li><li class="listitem">
HPUX now correctly defaults to using /dev/poll, which should
increase performance. [RT #21919]
</li><li class="listitem">
If named is running as a threaded application, after an "rndc stop"
command has been issued, other inbound TCP requests can cause named
to hang and never complete shutdown. [RT #22108]
</li><li class="listitem">
After an "rndc reconfig", the refresh timer for managed-keys is ignored, resulting in managed-keys
not being refreshed until named is restarted. [RT #22296]
</li><li class="listitem">
An NSEC3PARAM record placed inside a zone which is not properly
signed with NSEC3 could cause named to crash, if changed via dynamic
update. [RT #22363]
</li><li class="listitem">
"rndc -h" now includes "loadkeys" option. [RT #22493]
</li><li class="listitem">
When performing a GSS-TSIG signed dynamic zone update, memory could be
leaked. This causes an unclean shutdown and may affect long-running
servers. [RT #22573]
</li><li class="listitem">
A bug in NetBSD and FreeBSD kernels with SO_ACCEPTFILTER enabled allows
for a TCP DoS attack. Until there is a kernel fix, ISC is disabling
SO_ACCEPTFILTER support in BIND. [RT #22589]
</li><li class="listitem">
When signing records, named didn't filter out any TTL changes
to DNSKEY records. This resulted in an incomplete key set. TTL
changes are now dealt with before signing.
[RT #22590]
</li><li class="listitem">
Corrected a defect where a combination of dynamic updates and zone transfers incorrectly locked the in-memory zone database, causing
named to freeze. [RT #22614]
</li><li class="listitem">
Don't run MX checks (check-mx) when the MX record points to ".".
[RT #22645]
</li><li class="listitem">
DST key reference counts can now be incremented via dst_key_attach.
[RT #22672]
</li><li class="listitem">
The IN6_IS_ADDR_LINKLOCAL and
IN6_IS_ADDR_SITELOCAL macros in win32 were updated/corrected
per current Windows OS. [RT #22724]
</li><li class="listitem">
"dnssec-settime -S" no longer tests prepublication interval validity
when the interval is set to 0. [RT #22761]
</li><li class="listitem">
isc_mutex_init_errcheck() in phtreads/mutex.c failed to destroy attr. [RT #22766]
</li><li class="listitem">
The Kerberos realm was being truncated when being pulled from the
the host prinicipal, make krb5-self updates fail. [RT #22770]
</li><li class="listitem">
named failed to preserve the case of domain names in RDATA which is not compressible when writing master files. [RT #22863]
</li><li class="listitem">
The man page for dnssec-keyfromlabel incorrectly had "-U" rather
than the correct option "-I". [RT #22887]
</li><li class="listitem">
The "rndc" command usage statement was missing the "-b" option.
[RT #22937]
</li><li class="listitem">
There was a bug in how the clients-per-query code worked with some
query patterns. This could result, in rare circumstances, in having all
the client query slots filled with queries for the same DNS label,
essentially ignoring the max-clients-per-query setting.
[RT #22972]
</li><li class="listitem">
The secure zone update feature in named is based on the zone
being signed and configured for dynamic updates. A bug in the ACL
processing for "allow-update { none; };" resulted in a zone that is
supposed to be static being treated as a dynamic zone. Thus, name
would try to sign/re-sign that zone erroneously. [RT #23120]
</li></ul></div>
</div>
<div class="section" title="9.7.2-P3"><div class="titlepage"><div><div><h3 class="title"><a id="id3415913"></a>9.7.2-P3</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
Microsoft changed the behavior of sockets between NT/XP based
stacks vs Vista/windows7 stacks. Server 2003/2008 have the older
behavior, 2008r2 has the new behavior. With the change, different
error results are possible, so ISC adapted BIND to handle the new
error results.
This resolves an issue where sockets would shut down on
Windows servers causing named to stop responding to queries.
[RT #21906]
</li><li class="listitem">
Windows has non-POSIX compliant behavior in its rename() and unlink()
calls. This caused journal compaction to fail on Windows BIND servers
with the log error: "dns_journal_compact failed: failure".
[RT #22434]
</li></ul></div>
</div>
<div class="section" title="9.7.2-P1"><div class="titlepage"><div><div><h3 class="title"><a id="id3416078"></a>9.7.2-P1</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
A bug, introduced in BIND 9.7.2, caused named to fail to start
if a master zone file was unreadable or missing. This has
been corrected in 9.7.2-P1.
</li><li class="listitem">
BIND previously accepted answers from authoritative servers that did
not provide a "proper" response, such as not setting AA bit. BIND was
changed to be more strict in what it accepted but this caused
operational issues. This new strictness has been backed out in
9.7.2-P1.
</li></ul></div>
</div>
<div class="section" title="9.7.2"><div class="titlepage"><div><div><h3 class="title"><a id="id3416105"></a>9.7.2</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
Removed a warning message when running BIND 9 under Windows
for when a TCP connection was aborted. This is a common
occurrence and the warning was extraneous.
</li><li class="listitem">
Worked around a race condition in the cache database memory
handling. Without this fix a DNS cache DB or ADB could
incorrectly stay in an over memory state, effectively refusing
further caching, which subsequently made a BIND 9 caching
server unworkable.
</li><li class="listitem">
Partially disabled change 2864 because it would cause
infinite attempts of RRSIG queries.
</li><li class="listitem">
BIND did not properly handle non-cacheable negative responses
from insecure zones. This caused several non-protocol-compliant
zones to become unresolvable. BIND is now more accepting of
responses it receives from less strict servers.
</li></ul></div>
</div>
</div>
<div class="section" title="Known issues in this release"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3416145"></a>Known issues in this release</h2></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
<p>
"make test" will fail on OSX and possibly other operating systems.
The failure occurs in a new test to check for allow-query ACLs.
The failure is caused because the source address is not specified on
the dig commands issued in the test.
</p>
<p>
If running "make test" is part of your usual acceptance process,
please edit the file <code class="code">bin/tests/system/allow_query/test.sh</code>
and add
</p><p>
<code class="code">-b 10.53.0.2</code>
</p><p>
to the <code class="code">DIGOPTS</code> line.
</p>
</li></ul></div>
</div>
<div class="section" title="Thank You"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3416192"></a>Thank You</h2></div></div></div>
<p>
Thank you to everyone who assisted us in making this release possible.
If you would like to contribute to ISC to assist us in continuing to make
quality open source software, please visit our donations page at
<a class="ulink" href="http://www.isc.org/supportisc" target="_top">http://www.isc.org/supportisc</a>.
</p>
</div>
</div></body></html>
Binary file not shown.
-220
View File
@@ -1,220 +0,0 @@
__________________________________________________________________
Introduction
BIND 9.7.3 is the current release of BIND 9.7.
This document summarizes changes from BIND 9.7.1 to BIND 9.7.3. Please
see the CHANGES file in the source code release for a complete list of
all changes.
Download
The latest development version of BIND 9 software can always be found
on our web site at http://www.isc.org/downloads/development. There you
will find additional information about each release, source code, and
some pre-compiled versions for certain operating systems.
Support
Product support information is available on
http://www.isc.org/services/support for paid support options. Free
support is provided by our user community via a mailing list.
Information on all public email lists is available at
https://lists.isc.org/mailman/listinfo.
New Features
9.7.2
* Zones may be dynamically added and removed with the "rndc addzone"
and "rndc delzone" commands. These dynamically added zones are
written to a per-view configuration file. Do not rely on the
configuration file name nor contents as this will change in a
future release. This is an experimental feature at this time.
* Added new "filter-aaaa-on-v4" access control list to select which
IPv4 clients have AAAA record filtering applied.
* A new command "rndc secroots" was added to dump a combined summary
of the currently managed keys combined with statically configured
trust anchors.
* Added support to load new keys into managed zones without signing
immediately with "rndc loadkeys". Added support to link keys with
"dnssec-keygen -S" and "dnssec-settime -S".
Feature Changes
9.7.2
* Documentation improvements
* ORCHID prefixes were removed from the automatic empty zone list.
* Improved handling of GSSAPI security contexts. Specifically, better
memory management of cached contexts, limited lifetime of a context
to 1 hour, and added a "realm" command to nsupdate to allow
selection of a non-default realm name.
* The contributed tool "zkt" was updated to version 1.0.
Security Fixes
9.7.2-P3
* Adding a NO DATA signed negative response to cache failed to clear
any matching RRSIG records already in cache. A subsequent lookup of
the cached NO DATA entry could crash named (INSIST) when the
unexpected RRSIG was also returned with the NO DATA cache entry.
[RT #22288] [CVE-2010-3613] [VU#706148]
* BIND, acting as a DNSSEC validator, was determining if the NS RRset
is insecure based on a value that could mean either that the RRset
is actually insecure or that there wasn't a matching key for the
RRSIG in the DNSKEY RRset when resuming from validating the DNSKEY
RRset. This can happen when in the middle of a DNSKEY algorithm
rollover, when two different algorithms were used to sign a zone
but only the new set of keys are in the zone DNSKEY RRset. [RT
#22309] [CVE-2010-3614] [VU#837744]
* When BIND is running as an authoritative server for a zone and
receives a query for that zone data, it first checks for
allow-query acls in the zone statement, then in that view, then in
global options. If none of these exist, it defaults to allowing any
query (allow-query {"any"};).
With this bug, if the allow-query is not set in the zone statement,
it failed to check in view or global options and fell back to the
default of allowing any query. This means that queries that the
zone owner did not wish to allow were incorrectly allowed. [RT
#22418] [CVE-2010-3615] [VU#510208]
9.7.2-P2
* A flaw where the wrong ACL was applied was fixed. This flaw allowed
access to a cache via recursion even though the ACL disallowed it.
9.7.2-P1
* If BIND, acting as a DNSSEC validating server, has two or more
trust anchors configured in named.conf for the same zone (such as
example.com) and the response for a record in that zone from the
authoritative server includes a bad signature, the validating
server will crash while trying to validate that query.
Bug Fixes
9.7.3
* BIND now builds with threads disabled in versions of NetBSD earlier
than 5.0 and with pthreads enabled by default in NetBSD versions
5.0 and higher. Also removes support for unproven-pthreads,
mit-pthreads and ptl2. [RT #19203]
* Added a regression test for fix 2896/RT #21045 ("rndc sign" failed
to properly update the zone when adding a DNSKEY for publication
only). [RT #21324]
* "nsupdate -l" now gives error message if "session.key" file is not
found. [RT #21670]
* HPUX now correctly defaults to using /dev/poll, which should
increase performance. [RT #21919]
* If named is running as a threaded application, after an "rndc stop"
command has been issued, other inbound TCP requests can cause named
to hang and never complete shutdown. [RT #22108]
* After an "rndc reconfig", the refresh timer for managed-keys is
ignored, resulting in managed-keys not being refreshed until named
is restarted. [RT #22296]
* An NSEC3PARAM record placed inside a zone which is not properly
signed with NSEC3 could cause named to crash, if changed via
dynamic update. [RT #22363]
* "rndc -h" now includes "loadkeys" option. [RT #22493]
* When performing a GSS-TSIG signed dynamic zone update, memory could
be leaked. This causes an unclean shutdown and may affect
long-running servers. [RT #22573]
* A bug in NetBSD and FreeBSD kernels with SO_ACCEPTFILTER enabled
allows for a TCP DoS attack. Until there is a kernel fix, ISC is
disabling SO_ACCEPTFILTER support in BIND. [RT #22589]
* When signing records, named didn't filter out any TTL changes to
DNSKEY records. This resulted in an incomplete key set. TTL changes
are now dealt with before signing. [RT #22590]
* Corrected a defect where a combination of dynamic updates and zone
transfers incorrectly locked the in-memory zone database, causing
named to freeze. [RT #22614]
* Don't run MX checks (check-mx) when the MX record points to ".".
[RT #22645]
* DST key reference counts can now be incremented via dst_key_attach.
[RT #22672]
* The IN6_IS_ADDR_LINKLOCAL and IN6_IS_ADDR_SITELOCAL macros in win32
were updated/corrected per current Windows OS. [RT #22724]
* "dnssec-settime -S" no longer tests prepublication interval
validity when the interval is set to 0. [RT #22761]
* isc_mutex_init_errcheck() in phtreads/mutex.c failed to destroy
attr. [RT #22766]
* The Kerberos realm was being truncated when being pulled from the
the host prinicipal, make krb5-self updates fail. [RT #22770]
* named failed to preserve the case of domain names in RDATA which is
not compressible when writing master files. [RT #22863]
* The man page for dnssec-keyfromlabel incorrectly had "-U" rather
than the correct option "-I". [RT #22887]
* The "rndc" command usage statement was missing the "-b" option. [RT
#22937]
* There was a bug in how the clients-per-query code worked with some
query patterns. This could result, in rare circumstances, in having
all the client query slots filled with queries for the same DNS
label, essentially ignoring the max-clients-per-query setting. [RT
#22972]
* The secure zone update feature in named is based on the zone being
signed and configured for dynamic updates. A bug in the ACL
processing for "allow-update { none; };" resulted in a zone that is
supposed to be static being treated as a dynamic zone. Thus, name
would try to sign/re-sign that zone erroneously. [RT #23120]
9.7.2-P3
* Microsoft changed the behavior of sockets between NT/XP based
stacks vs Vista/windows7 stacks. Server 2003/2008 have the older
behavior, 2008r2 has the new behavior. With the change, different
error results are possible, so ISC adapted BIND to handle the new
error results. This resolves an issue where sockets would shut down
on Windows servers causing named to stop responding to queries. [RT
#21906]
* Windows has non-POSIX compliant behavior in its rename() and
unlink() calls. This caused journal compaction to fail on Windows
BIND servers with the log error: "dns_journal_compact failed:
failure". [RT #22434]
9.7.2-P1
* A bug, introduced in BIND 9.7.2, caused named to fail to start if a
master zone file was unreadable or missing. This has been corrected
in 9.7.2-P1.
* BIND previously accepted answers from authoritative servers that
did not provide a "proper" response, such as not setting AA bit.
BIND was changed to be more strict in what it accepted but this
caused operational issues. This new strictness has been backed out
in 9.7.2-P1.
9.7.2
* Removed a warning message when running BIND 9 under Windows for
when a TCP connection was aborted. This is a common occurrence and
the warning was extraneous.
* Worked around a race condition in the cache database memory
handling. Without this fix a DNS cache DB or ADB could incorrectly
stay in an over memory state, effectively refusing further caching,
which subsequently made a BIND 9 caching server unworkable.
* Partially disabled change 2864 because it would cause infinite
attempts of RRSIG queries.
* BIND did not properly handle non-cacheable negative responses from
insecure zones. This caused several non-protocol-compliant zones to
become unresolvable. BIND is now more accepting of responses it
receives from less strict servers.
Known issues in this release
* "make test" will fail on OSX and possibly other operating systems.
The failure occurs in a new test to check for allow-query ACLs. The
failure is caused because the source address is not specified on
the dig commands issued in the test.
If running "make test" is part of your usual acceptance process,
please edit the file bin/tests/system/allow_query/test.sh and add
-b 10.53.0.2
to the DIGOPTS line.
Thank You
Thank you to everyone who assisted us in making this release possible.
If you would like to contribute to ISC to assist us in continuing to
make quality open source software, please visit our donations page at
http://www.isc.org/supportisc.
+2 -2
View File
@@ -1,6 +1,6 @@
/*
* Generated by bindkeys.pl 1.3.104.2 2010/06/20 23:46:24 tbox Exp
* From bind.keys 1.5.42.2 2011/01/04 19:14:48 each Exp
* Generated by bindkeys.pl 1.3.104.2 2010-06-20 23:46:24 tbox Exp
* From bind.keys 1.5.42.2 2011-01-04 19:14:48 each Exp
*/
#define TRUSTED_KEYS "\
# The bind.keys file is used to override built-in DNSSEC trust anchors\n\
+3 -3
View File
@@ -1,6 +1,6 @@
/*
* Generated by convertxsl.pl 1.14 2008/07/17 23:43:26 jinmei Exp
* From bind9.xsl 1.21 2009/01/27 23:47:54 tbox Exp
* Generated by convertxsl.pl 1.14 2008-07-17 23:43:26 jinmei Exp
* From bind9.xsl 1.21 2009-01-27 23:47:54 tbox Exp
*/
static char xslmsg[] =
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n"
@@ -20,7 +20,7 @@ static char xslmsg[] =
" - PERFORMANCE OF THIS SOFTWARE.\n"
"-->\n"
"\n"
"<!-- \045Id: bind9.xsl,v 1.21 2009/01/27 23:47:54 tbox Exp \045 -->\n"
"<!-- \045Id: bind9.xsl,v 1.21 2009-01-27 23:47:54 tbox Exp \045 -->\n"
"\n"
"<xsl:stylesheet version=\"1.0\"\n"
" xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\"\n"
+16 -3
View File
@@ -1,6 +1,6 @@
#!/bin/sh
#
# Copyright (C) 2004, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2007, 2010, 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,17 +14,30 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: clean.sh,v 1.5.476.2 2010/05/27 23:49:55 tbox Exp $
# $Id: clean.sh,v 1.5.476.2.44.2 2011/06/06 23:46:30 tbox Exp $
rm -f random.data
rm -f ns*/named.run
rm -f ns1/K*
rm -f ns1/dsset-*
rm -f ns1/*.signed
rm -f ns1/signer.err
rm -f ns1/root.db
rm -f ns2/K*
rm -f ns2/dlvset-*
rm -f ns2/dsset-*
rm -f ns2/*.signed
rm -f ns2/*.pre
rm -f ns2/signer.err
rm -f ns2/druz.db
rm -f ns3/K*
rm -f ns3/*.db
rm -f ns3/*.signed
rm -f ns3/dlvset-*
rm -f ns3/dsset-*
rm -f ns3/keyset-*
rm -f ns3/trusted.conf ns5/trusted.conf
rm -f ns1/trusted.conf ns5/trusted.conf
rm -f ns3/trusted-dlv.conf ns5/trusted-dlv.conf
rm -f ns3/signer.err
rm -f ns6/K*
rm -f ns6/*.db
+4 -4
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2007, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named.conf,v 1.4 2007/06/19 23:47:02 tbox Exp $ */
/* $Id: named.conf,v 1.4.966.2 2011/06/06 23:46:30 tbox Exp $ */
controls { /* empty */ };
@@ -28,8 +28,8 @@ options {
listen-on-v6 { none; };
recursion no;
notify yes;
dnssec-enable no;
dnssec-enable yes;
};
zone "." { type master; file "root.db"; };
zone "." { type master; file "root.signed"; };
zone "rootservers.utld" { type master; file "rootservers.utld.db"; };
@@ -1,4 +1,4 @@
; Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
; Copyright (C) 2011 Internet Systems Consortium, Inc. ("ISC")
;
; Permission to use, copy, modify, and/or distribute this software for any
; purpose with or without fee is hereby granted, provided that the above
@@ -12,7 +12,7 @@
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
; PERFORMANCE OF THIS SOFTWARE.
; $Id: root.db,v 1.4 2007/06/19 23:47:02 tbox Exp $
; $Id: root.db.in,v 1.3.4.3 2011/06/06 23:46:30 tbox Exp $
$TTL 120
@ SOA ns.rootservers.utld hostmaster.ns.rootservers.utld (
@@ -22,3 +22,5 @@ ns A 10.53.0.1
;
utld NS ns.utld
ns.utld A 10.53.0.2
druz NS ns.druz
ns.druz A 10.53.0.2
+52
View File
@@ -0,0 +1,52 @@
#!/bin/sh
#
# Copyright (C) 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
# copyright notice and this permission notice appear in all copies.
#
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: sign.sh,v 1.3.4.3 2011/06/06 23:46:30 tbox Exp $
(cd ../ns2 && sh -e ./sign.sh || exit 1)
echo "I:dlv/ns1/sign.sh"
SYSTEMTESTTOP=../..
. $SYSTEMTESTTOP/conf.sh
RANDFILE=../random.data
zone=.
infile=root.db.in
zonefile=root.db
outfile=root.signed
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -g -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
grep -v '^;' $keyname2.key | $PERL -n -e '
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
local $key = join("", @rest);
print <<EOF
trusted-keys {
"$dn" $flags $proto $alg "$key";
};
EOF
' > trusted.conf
cp trusted.conf ../ns5
+54
View File
@@ -0,0 +1,54 @@
; Copyright (C) 2011 Internet Systems Consortium, Inc. ("ISC")
;
; Permission to use, copy, modify, and/or distribute this software for any
; purpose with or without fee is hereby granted, provided that the above
; copyright notice and this permission notice appear in all copies.
;
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
; PERFORMANCE OF THIS SOFTWARE.
; $Id: druz.db.in,v 1.4.4.3 2011/06/06 23:46:31 tbox Exp $
$TTL 120
@ SOA ns hostmaster.ns 1 3600 1200 604800 60
@ NS ns
ns A 10.53.0.2
;
rootservers NS ns.rootservers
ns.rootservers A 10.53.0.1
;
;
child1 NS ns.child1
ns.child1 A 10.53.0.3
;
child2 NS ns.child2
ns.child2 A 10.53.0.4
;
child3 NS ns.child3
ns.child3 A 10.53.0.3
;
child4 NS ns.child4
ns.child4 A 10.53.0.3
;
child5 NS ns.child5
ns.child5 A 10.53.0.3
;
child6 NS ns.child6
ns.child6 A 10.53.0.4
;
child7 NS ns.child7
ns.child7 A 10.53.0.3
;
child8 NS ns.child8
ns.child8 A 10.53.0.3
;
child9 NS ns.child9
ns.child9 A 10.53.0.3
;
child10 NS ns.child10
ns.child10 A 10.53.0.3
+4 -3
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2007, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named.conf,v 1.4 2007/06/19 23:47:02 tbox Exp $ */
/* $Id: named.conf,v 1.4.966.2 2011/06/06 23:46:31 tbox Exp $ */
controls { /* empty */ };
@@ -28,8 +28,9 @@ options {
listen-on-v6 { none; };
recursion no;
notify yes;
dnssec-enable no;
dnssec-enable yes;
};
zone "." { type hint; file "hints"; };
zone "utld" { type master; file "utld.db"; };
zone "druz" { type master; file "druz.signed"; };
+44
View File
@@ -0,0 +1,44 @@
#!/bin/sh
#
# Copyright (C) 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
# copyright notice and this permission notice appear in all copies.
#
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: sign.sh,v 1.3.4.3 2011/06/06 23:46:31 tbox Exp $
(cd ../ns3 && sh -e ./sign.sh || exit 1)
echo "I:dlv/ns2/sign.sh"
SYSTEMTESTTOP=../..
. $SYSTEMTESTTOP/conf.sh
RANDFILE=../random.data
zone=druz.
infile=druz.db.in
zonefile=druz.db
outfile=druz.pre
dlvzone=utld.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -g -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
$CHECKZONE -q -D -i none druz druz.pre |
sed '/IN DNSKEY/s/\([a-z0-9A-Z/]\{10\}\)[a-z0-9A-Z/]\{16\}/\1XXXXXXXXXXXXXXXX/'> druz.signed
echo "I: signed $zone"
+10 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2007, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named.conf,v 1.4 2007/06/19 23:47:02 tbox Exp $ */
/* $Id: named.conf,v 1.4.966.2 2011/06/06 23:46:31 tbox Exp $ */
controls { /* empty */ };
@@ -41,3 +41,11 @@ zone "child7.utld" { type master; file "child7.signed"; }; // no dlv
zone "child8.utld" { type master; file "child8.signed"; }; // no dlv
zone "child9.utld" { type master; file "child9.signed"; }; // dlv
zone "child10.utld" { type master; file "child.db.in"; }; // dlv unsigned
zone "child1.druz" { type master; file "child1.druz.signed"; }; // dlv
zone "child3.druz" { type master; file "child3.druz.signed"; }; // dlv
zone "child4.druz" { type master; file "child4.druz.signed"; }; // dlv
zone "child5.druz" { type master; file "child5.druz.signed"; }; // dlv
zone "child7.druz" { type master; file "child7.druz.signed"; }; // no dlv
zone "child8.druz" { type master; file "child8.druz.signed"; }; // no dlv
zone "child9.druz" { type master; file "child9.druz.signed"; }; // dlv
zone "child10.druz" { type master; file "child.db.in"; }; // dlv unsigned
+132 -13
View File
@@ -1,6 +1,6 @@
#!/bin/sh
#
# Copyright (C) 2004, 2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,21 +14,24 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: sign.sh,v 1.6.32.3 2010/05/27 23:49:55 tbox Exp $
# $Id: sign.sh,v 1.6.32.3.44.2 2011/06/06 23:46:31 tbox Exp $
(cd ../ns6 && sh -e ./sign.sh)
echo "I:dlv/ns3/sign.sh"
SYSTEMTESTTOP=../..
. $SYSTEMTESTTOP/conf.sh
RANDFILE=../random.data
dlvzone=dlv.utld.
dlvsets=
dssets=
zone=child1.utld.
infile=child.db.in
zonefile=child1.utld.db
outfile=child1.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -44,7 +47,6 @@ zone=child3.utld.
infile=child.db.in
zonefile=child3.utld.db
outfile=child3.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -60,7 +62,6 @@ zone=child4.utld.
infile=child.db.in
zonefile=child4.utld.db
outfile=child4.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -76,7 +77,6 @@ zone=child5.utld.
infile=child.db.in
zonefile=child5.utld.db
outfile=child5.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -92,7 +92,6 @@ zone=child7.utld.
infile=child.db.in
zonefile=child7.utld.db
outfile=child7.signed
dlvzone=dlv.utld.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -107,7 +106,6 @@ zone=child8.utld.
infile=child.db.in
zonefile=child8.utld.db
outfile=child8.signed
dlvzone=dlv.utld.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -122,7 +120,6 @@ zone=child9.utld.
infile=child.db.in
zonefile=child9.utld.db
outfile=child9.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -137,7 +134,6 @@ zone=child10.utld.
infile=child.db.in
zonefile=child10.utld.db
outfile=child10.signed
dlvzone=dlv.utld.
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -148,12 +144,133 @@ cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child1.druz.
infile=child.db.in
zonefile=child1.druz.db
outfile=child1.druz.signed
dlvsets="$dlvsets dlvset-$zone"
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key ../ns6/dsset-grand.$zone >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child3.druz.
infile=child.db.in
zonefile=child3.druz.db
outfile=child3.druz.signed
dlvsets="$dlvsets dlvset-$zone"
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key ../ns6/dsset-grand.$zone >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child4.druz.
infile=child.db.in
zonefile=child4.druz.db
outfile=child4.druz.signed
dlvsets="$dlvsets dlvset-$zone"
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child5.druz.
infile=child.db.in
zonefile=child5.druz.db
outfile=child5.druz.signed
dlvsets="$dlvsets dlvset-$zone"
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key ../ns6/dsset-grand.$zone >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child7.druz.
infile=child.db.in
zonefile=child7.druz.db
outfile=child7.druz.signed
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key ../ns6/dsset-grand.$zone >$zonefile
$SIGNER -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child8.druz.
infile=child.db.in
zonefile=child8.druz.db
outfile=child8.druz.signed
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child9.druz.
infile=child.db.in
zonefile=child9.druz.db
outfile=child9.druz.signed
dlvsets="$dlvsets dlvset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=child10.druz.
infile=child.db.in
zonefile=child10.druz.db
outfile=child10.druz.signed
dlvsets="$dlvsets dlvset-$zone"
dssets="$dssets dsset-$zone"
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -r $RANDFILE -l $dlvzone -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=dlv.utld.
infile=dlv.db.in
zonefile=dlv.utld.db
outfile=dlv.signed
dlvzone=dlv.utld.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
@@ -172,5 +289,7 @@ trusted-keys {
"$dn" $flags $proto $alg "$key";
};
EOF
' > trusted.conf
cp trusted.conf ../ns5
' > trusted-dlv.conf
cp trusted-dlv.conf ../ns5
cp $dssets ../ns2
+3 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2006, 2007, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named.conf,v 1.8 2007/06/18 23:47:28 tbox Exp $ */
/* $Id: named.conf,v 1.8.966.2 2011/06/06 23:46:31 tbox Exp $ */
/*
* Choose a keyname that is unlikely to clash with any real key names.
@@ -46,6 +46,7 @@ controls {
};
include "trusted.conf";
include "trusted-dlv.conf";
options {
query-source address 10.53.0.5;
+10 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2010, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named.conf,v 1.2.2.3 2010/07/11 01:18:17 each Exp $ */
/* $Id: named.conf,v 1.2.2.3.34.2 2011/06/06 23:46:31 tbox Exp $ */
controls { /* empty */ };
@@ -40,3 +40,11 @@ zone "grand.child7.utld" { type master; file "grand.child7.signed"; };
zone "grand.child8.utld" { type master; file "grand.child8.signed"; };
zone "grand.child9.utld" { type master; file "grand.child9.signed"; };
zone "grand.child10.utld" { type master; file "grand.child10.signed"; };
zone "grand.child1.druz" { type master; file "grand.child1.druz.signed"; };
zone "grand.child3.druz" { type master; file "grand.child3.druz.signed"; };
zone "grand.child4.druz" { type master; file "grand.child4.druz.signed"; };
zone "grand.child5.druz" { type master; file "grand.child5.druz.signed"; };
zone "grand.child7.druz" { type master; file "grand.child7.druz.signed"; };
zone "grand.child8.druz" { type master; file "grand.child8.druz.signed"; };
zone "grand.child9.druz" { type master; file "grand.child9.druz.signed"; };
zone "grand.child10.druz" { type master; file "grand.child10.druz.signed"; };
+121 -2
View File
@@ -1,6 +1,6 @@
#!/bin/sh
#
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2010, 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,11 +14,13 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: sign.sh,v 1.2.2.2 2010/05/27 23:49:55 tbox Exp $
# $Id: sign.sh,v 1.2.2.2.44.2 2011/06/06 23:46:31 tbox Exp $
SYSTEMTESTTOP=../..
. $SYSTEMTESTTOP/conf.sh
echo "I:dlv/ns6/sign.sh"
RANDFILE=../random.data
zone=grand.child1.utld.
@@ -137,3 +139,120 @@ cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child1.druz.
infile=child.db.in
zonefile=grand.child1.druz.db
outfile=grand.child1.druz.signed
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child3.druz.
infile=child.db.in
zonefile=grand.child3.druz.db
outfile=grand.child3.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child4.druz.
infile=child.db.in
zonefile=grand.child4.druz.db
outfile=grand.child4.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child5.druz.
infile=child.db.in
zonefile=grand.child5.druz.db
outfile=grand.child5.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child7.druz.
infile=child.db.in
zonefile=grand.child7.druz.db
outfile=grand.child7.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child8.druz.
infile=child.db.in
zonefile=grand.child8.druz.db
outfile=grand.child8.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child9.druz.
infile=child.db.in
zonefile=grand.child9.druz.db
outfile=grand.child9.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
zone=grand.child10.druz.
infile=child.db.in
zonefile=grand.child10.druz.db
outfile=grand.child10.druz.signed
dlvzone=dlv.druz.
keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
cat $infile $keyname1.key $keyname2.key >$zonefile
$SIGNER -g -r $RANDFILE -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
echo "I: signed $zone"
+3 -3
View File
@@ -1,6 +1,6 @@
#!/bin/sh
#
# Copyright (C) 2004, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,8 +14,8 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: setup.sh,v 1.6 2009/03/02 23:47:43 tbox Exp $
# $Id: setup.sh,v 1.6.542.2 2011/06/06 23:46:30 tbox Exp $
../../../tools/genrandom 400 random.data
(cd ns3 && sh -e sign.sh)
(cd ns1 && sh -e sign.sh)
+18 -2
View File
@@ -1,6 +1,6 @@
#!/bin/sh
#
# Copyright (C) 2004, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2007, 2010, 2011 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: tests.sh,v 1.4.558.2 2010/05/27 23:49:55 tbox Exp $
# $Id: tests.sh,v 1.4.558.2.44.2 2011/06/06 23:46:30 tbox Exp $
SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh
@@ -42,5 +42,21 @@ n=`expr $n + 1`
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
echo "I:checking that SOA reference by DLV in a DRUZ with DS validates as secure ($n)"
ret=0
$DIG $DIGOPTS child1.druz soa @10.53.0.5 > dig.out.ns5.test$n || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns5.test$n > /dev/null || ret=1
n=`expr $n + 1`
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
echo "I:checking that child SOA reference by DLV in a DRUZ with DS validates as secure ($n)"
ret=0
$DIG $DIGOPTS grand.child1.druz soa @10.53.0.5 > dig.out.ns5.test$n || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns5.test$n > /dev/null || ret=1
n=`expr $n + 1`
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
echo "I:exit status: $status"
exit $status
+2 -2
View File
@@ -1,6 +1,6 @@
# $Id: SRCID,v 1.73.2.393 2011/02/08 02:16:05 tbox Exp $
# $Id: SRCID,v 1.73.2.393.8.9 2011/06/21 20:16:33 tbox Exp $
#
# This file must follow /bin/sh rules. It is imported directly via
# configure.
#
SRCID="( $Date: 2011/02/08 02:16:05 $ )"
SRCID="( $Date: 2011/06/21 20:16:33 $ )"
+1 -1
View File
@@ -1,3 +1,3 @@
LIBINTERFACE = 70
LIBREVISION = 2
LIBREVISION = 4
LIBAGE = 1
+5 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2008, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: masterdump.h,v 1.42 2008/09/24 02:46:23 marka Exp $ */
/* $Id: masterdump.h,v 1.42.604.2 2011/06/06 23:46:32 tbox Exp $ */
#ifndef DNS_MASTERDUMP_H
#define DNS_MASTERDUMP_H 1
@@ -334,6 +334,9 @@ dns_master_styledestroy(dns_master_style_t **style, isc_mem_t *mctx);
const char *
dns_trust_totext(dns_trust_t trust);
/*%<
* Display trust in textual form.
*/
ISC_LANG_ENDDECLS
+9 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: rdataset.h,v 1.67.186.2 2010/02/25 05:25:53 tbox Exp $ */
/* $Id: rdataset.h,v 1.67.186.2.48.3 2011/06/21 20:14:48 each Exp $ */
#ifndef DNS_RDATASET_H
#define DNS_RDATASET_H 1
@@ -203,6 +203,7 @@ struct dns_rdataset {
#define DNS_RDATASETATTR_RESIGN 0x00040000
#define DNS_RDATASETATTR_CLOSEST 0x00080000
#define DNS_RDATASETATTR_OPTOUT 0x00100000 /*%< OPTOUT proof */
#define DNS_RDATASETATTR_NEGATIVE 0x00200000
/*%
* _OMITDNSSEC:
@@ -650,6 +651,12 @@ dns_rdataset_expire(dns_rdataset_t *rdataset);
* Mark the rdataset to be expired in the backing database.
*/
const char *
dns_trust_totext(dns_trust_t trust);
/*%<
* Display trust in textual form.
*/
ISC_LANG_ENDDECLS
#endif /* DNS_RDATASET_H */
+16 -41
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: masterdump.c,v 1.99 2009/11/17 23:55:18 marka Exp $ */
/* $Id: masterdump.c,v 1.99.334.3 2011/06/21 20:14:46 each Exp $ */
/*! \file */
@@ -410,6 +410,7 @@ rdataset_totext(dns_rdataset_t *rdataset,
isc_uint32_t current_ttl;
isc_boolean_t current_ttl_valid;
dns_rdatatype_t type;
unsigned int type_start;
REQUIRE(DNS_RDATASET_VALID(rdataset));
@@ -491,29 +492,26 @@ rdataset_totext(dns_rdataset_t *rdataset,
* Type.
*/
if (rdataset->type == 0) {
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0) {
type = rdataset->covers;
} else {
type = rdataset->type;
}
{
unsigned int type_start;
INDENT_TO(type_column);
type_start = target->used;
if (rdataset->type == 0)
RETERR(str_totext("\\-", target));
result = dns_rdatatype_totext(type, target);
if (result != ISC_R_SUCCESS)
return (result);
column += (target->used - type_start);
}
INDENT_TO(type_column);
type_start = target->used;
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0)
RETERR(str_totext("\\-", target));
result = dns_rdatatype_totext(type, target);
if (result != ISC_R_SUCCESS)
return (result);
column += (target->used - type_start);
/*
* Rdata.
*/
INDENT_TO(rdata_column);
if (rdataset->type == 0) {
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0) {
if (NXDOMAIN(rdataset))
RETERR(str_totext(";-$NXDOMAIN\n", target));
else
@@ -835,26 +833,6 @@ dump_order_compare(const void *a, const void *b) {
#define MAXSORT 64
static const char *trustnames[] = {
"none",
"pending-additional",
"pending-answer",
"additional",
"glue",
"answer",
"authauthority",
"authanswer",
"secure",
"local" /* aka ultimate */
};
const char *
dns_trust_totext(dns_trust_t trust) {
if (trust >= sizeof(trustnames)/sizeof(*trustnames))
return ("bad");
return (trustnames[trust]);
}
static isc_result_t
dump_rdatasets_text(isc_mem_t *mctx, dns_name_t *name,
dns_rdatasetiter_t *rdsiter, dns_totext_ctx_t *ctx,
@@ -894,12 +872,9 @@ dump_rdatasets_text(isc_mem_t *mctx, dns_name_t *name,
for (i = 0; i < n; i++) {
dns_rdataset_t *rds = sorted[i];
if (ctx->style.flags & DNS_STYLEFLAG_TRUST) {
unsigned int trust = rds->trust;
INSIST(trust < (sizeof(trustnames) /
sizeof(trustnames[0])));
fprintf(f, "; %s\n", trustnames[trust]);
fprintf(f, "; %s\n", dns_trust_totext(rds->trust));
}
if (rds->type == 0 &&
if (((rds->attributes & DNS_RDATASETATTR_NEGATIVE) != 0) &&
(ctx->style.flags & DNS_STYLEFLAG_NCACHE) == 0) {
/* Omit negative cache entries */
} else {
@@ -1064,7 +1039,7 @@ dump_rdatasets_raw(isc_mem_t *mctx, dns_name_t *name,
dns_rdataset_init(&rdataset);
dns_rdatasetiter_current(rdsiter, &rdataset);
if (rdataset.type == 0 &&
if (((rdataset.attributes & DNS_RDATASETATTR_NEGATIVE) != 0) &&
(ctx->style.flags & DNS_STYLEFLAG_NCACHE) == 0) {
/* Omit negative cache entries */
} else {
+7 -7
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: message.c,v 1.249.10.4 2010/06/03 05:27:59 marka Exp $ */
/* $Id: message.c,v 1.249.10.4.36.3 2011/06/21 20:14:46 each Exp $ */
/*! \file */
@@ -2516,7 +2516,7 @@ dns_message_peekheader(isc_buffer_t *source, dns_messageid_t *idp,
isc_result_t
dns_message_reply(dns_message_t *msg, isc_boolean_t want_question_section) {
unsigned int first_section;
unsigned int clear_after;
isc_result_t result;
REQUIRE(DNS_MESSAGE_VALID(msg));
@@ -2528,15 +2528,15 @@ dns_message_reply(dns_message_t *msg, isc_boolean_t want_question_section) {
msg->opcode != dns_opcode_notify)
want_question_section = ISC_FALSE;
if (msg->opcode == dns_opcode_update)
first_section = DNS_SECTION_ADDITIONAL;
clear_after = DNS_SECTION_PREREQUISITE;
else if (want_question_section) {
if (!msg->question_ok)
return (DNS_R_FORMERR);
first_section = DNS_SECTION_ANSWER;
clear_after = DNS_SECTION_ANSWER;
} else
first_section = DNS_SECTION_QUESTION;
clear_after = DNS_SECTION_QUESTION;
msg->from_to_wire = DNS_MESSAGE_INTENTRENDER;
msgresetnames(msg, first_section);
msgresetnames(msg, clear_after);
msgresetopt(msg);
msgresetsigs(msg, ISC_TRUE);
msginitprivate(msg);
+8 -3
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007, 2008, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007, 2008, 2010, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: ncache.c,v 1.43.268.7 2010/05/19 09:51:31 marka Exp $ */
/* $Id: ncache.c,v 1.43.268.7.46.3 2011/06/21 20:14:46 each Exp $ */
/*! \file */
@@ -186,7 +186,7 @@ dns_ncache_addoptout(dns_message_t *message, dns_db_t *cache,
*/
isc_buffer_availableregion(&buffer,
&r);
if (r.length < 2)
if (r.length < 3)
return (ISC_R_NOSPACE);
isc_buffer_putuint16(&buffer,
rdataset->type);
@@ -294,6 +294,7 @@ dns_ncache_addoptout(dns_message_t *message, dns_db_t *cache,
RUNTIME_CHECK(dns_rdatalist_tordataset(&ncrdatalist, &ncrdataset)
== ISC_R_SUCCESS);
ncrdataset.trust = trust;
ncrdataset.attributes |= DNS_RDATASETATTR_NEGATIVE;
if (message->rcode == dns_rcode_nxdomain)
ncrdataset.attributes |= DNS_RDATASETATTR_NXDOMAIN;
if (optout)
@@ -324,6 +325,7 @@ dns_ncache_towire(dns_rdataset_t *rdataset, dns_compress_t *cctx,
REQUIRE(rdataset != NULL);
REQUIRE(rdataset->type == 0);
REQUIRE((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0);
savedbuffer = *target;
count = 0;
@@ -552,6 +554,7 @@ dns_ncache_getrdataset(dns_rdataset_t *ncacherdataset, dns_name_t *name,
REQUIRE(ncacherdataset != NULL);
REQUIRE(ncacherdataset->type == 0);
REQUIRE((ncacherdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0);
REQUIRE(name != NULL);
REQUIRE(!dns_rdataset_isassociated(rdataset));
REQUIRE(type != dns_rdatatype_rrsig);
@@ -628,6 +631,7 @@ dns_ncache_getsigrdataset(dns_rdataset_t *ncacherdataset, dns_name_t *name,
REQUIRE(ncacherdataset != NULL);
REQUIRE(ncacherdataset->type == 0);
REQUIRE((ncacherdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0);
REQUIRE(name != NULL);
REQUIRE(!dns_rdataset_isassociated(rdataset));
@@ -727,6 +731,7 @@ dns_ncache_current(dns_rdataset_t *ncacherdataset, dns_name_t *found,
REQUIRE(ncacherdataset != NULL);
REQUIRE(ncacherdataset->type == 0);
REQUIRE((ncacherdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0);
REQUIRE(found != NULL);
REQUIRE(!dns_rdataset_isassociated(rdataset));
+7 -7
View File
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: nsec3.c,v 1.13.6.6 2010/12/07 03:01:40 marka Exp $ */
/* $Id: nsec3.c,v 1.13.6.6.12.1 2011/06/21 20:14:47 each Exp $ */
#include <config.h>
@@ -1579,7 +1579,7 @@ dns_nsec3_delnsec3s(dns_db_t *db, dns_dbversion_t *version, dns_name_t *name,
isc_result_t
dns_nsec3_delnsec3sx(dns_db_t *db, dns_dbversion_t *version, dns_name_t *name,
dns_rdatatype_t type, dns_diff_t *diff)
dns_rdatatype_t privatetype, dns_diff_t *diff)
{
dns_dbnode_t *node = NULL;
dns_rdata_nsec3param_t nsec3param;
@@ -1624,9 +1624,9 @@ dns_nsec3_delnsec3sx(dns_db_t *db, dns_dbversion_t *version, dns_name_t *name,
dns_rdataset_disassociate(&rdataset);
try_private:
if (type == 0)
if (privatetype == 0)
goto success;
result = dns_db_findrdataset(db, node, version, type, 0, 0,
result = dns_db_findrdataset(db, node, version, privatetype, 0, 0,
&rdataset, NULL);
if (result == ISC_R_NOTFOUND)
goto success;
@@ -1681,7 +1681,7 @@ dns_nsec3_active(dns_db_t *db, dns_dbversion_t *version,
isc_result_t
dns_nsec3_activex(dns_db_t *db, dns_dbversion_t *version,
isc_boolean_t complete, dns_rdatatype_t type,
isc_boolean_t complete, dns_rdatatype_t privatetype,
isc_boolean_t *answer)
{
dns_dbnode_t *node = NULL;
@@ -1730,11 +1730,11 @@ dns_nsec3_activex(dns_db_t *db, dns_dbversion_t *version,
*answer = ISC_FALSE;
try_private:
if (type == 0 || complete) {
if (privatetype == 0 || complete) {
*answer = ISC_FALSE;
return (ISC_R_SUCCESS);
}
result = dns_db_findrdataset(db, node, version, type, 0, 0,
result = dns_db_findrdataset(db, node, version, privatetype, 0, 0,
&rdataset, NULL);
dns_db_detachnode(db, &node);
+19 -10
View File
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: rbtdb.c,v 1.292.8.15 2010/12/02 05:07:03 marka Exp $ */
/* $Id: rbtdb.c,v 1.292.8.15.10.1 2011/06/21 20:14:47 each Exp $ */
/*! \file */
@@ -278,6 +278,7 @@ typedef ISC_LIST(dns_rbtnode_t) rbtnodelist_t;
#define RDATASET_ATTR_RESIGN 0x0020
#define RDATASET_ATTR_STATCOUNT 0x0040
#define RDATASET_ATTR_OPTOUT 0x0080
#define RDATASET_ATTR_NEGATIVE 0x0100
typedef struct acache_cbarg {
dns_rdatasetadditional_t type;
@@ -316,6 +317,8 @@ struct acachectl {
(((header)->attributes & RDATASET_ATTR_RESIGN) != 0)
#define OPTOUT(header) \
(((header)->attributes & RDATASET_ATTR_OPTOUT) != 0)
#define NEGATIVE(header) \
(((header)->attributes & RDATASET_ATTR_NEGATIVE) != 0)
#define DEFAULT_NODE_LOCK_COUNT 7 /*%< Should be prime. */
@@ -691,11 +694,13 @@ update_rrsetstats(dns_rbtdb_t *rbtdb, rdatasetheader_t *header,
/* At the moment we count statistics only for cache DB */
INSIST(IS_CACHE(rbtdb));
if (NXDOMAIN(header))
statattributes = DNS_RDATASTATSTYPE_ATTR_NXDOMAIN;
else if (RBTDB_RDATATYPE_BASE(header->type) == 0) {
statattributes = DNS_RDATASTATSTYPE_ATTR_NXRRSET;
base = RBTDB_RDATATYPE_EXT(header->type);
if (NEGATIVE(header)) {
if (NXDOMAIN(header))
statattributes = DNS_RDATASTATSTYPE_ATTR_NXDOMAIN;
else {
statattributes = DNS_RDATASTATSTYPE_ATTR_NXRRSET;
base = RBTDB_RDATATYPE_EXT(header->type);
}
} else
base = RBTDB_RDATATYPE_BASE(header->type);
@@ -2748,6 +2753,8 @@ bind_rdataset(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node,
rdataset->covers = RBTDB_RDATATYPE_EXT(header->type);
rdataset->ttl = header->rdh_ttl - now;
rdataset->trust = header->trust;
if (NEGATIVE(header))
rdataset->attributes |= DNS_RDATASETATTR_NEGATIVE;
if (NXDOMAIN(header))
rdataset->attributes |= DNS_RDATASETATTR_NXDOMAIN;
if (OPTOUT(header))
@@ -4785,7 +4792,7 @@ cache_find(dns_db_t *db, dns_name_t *name, dns_dbversion_t *version,
*nodep = node;
}
if (RBTDB_RDATATYPE_BASE(found->type) == 0) {
if (NEGATIVE(found)) {
/*
* We found a negative cache entry.
*/
@@ -5454,7 +5461,7 @@ cache_findrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
if (found == NULL)
return (ISC_R_NOTFOUND);
if (RBTDB_RDATATYPE_BASE(found->type) == 0) {
if (NEGATIVE(found)) {
/*
* We found a negative cache entry.
*/
@@ -5665,7 +5672,7 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
negtype = 0;
if (rbtversion == NULL && !newheader_nx) {
rdtype = RBTDB_RDATATYPE_BASE(newheader->type);
if (rdtype == 0) {
if (NEGATIVE(newheader)) {
/*
* We're adding a negative cache entry.
*/
@@ -6207,6 +6214,8 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
} else {
newheader->serial = 1;
newheader->resign = 0;
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0)
newheader->attributes |= RDATASET_ATTR_NEGATIVE;
if ((rdataset->attributes & DNS_RDATASETATTR_NXDOMAIN) != 0)
newheader->attributes |= RDATASET_ATTR_NXDOMAIN;
if ((rdataset->attributes & DNS_RDATASETATTR_OPTOUT) != 0)
@@ -7899,7 +7908,7 @@ rdatasetiter_next(dns_rdatasetiter_t *iterator) {
type = header->type;
rdtype = RBTDB_RDATATYPE_BASE(header->type);
if (rdtype == 0) {
if (NEGATIVE(header)) {
covers = RBTDB_RDATATYPE_EXT(header->type);
negtype = RBTDB_RDATATYPE_VALUE(covers, 0);
} else
+23 -3
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: rdataset.c,v 1.84.186.2 2010/02/25 05:25:51 tbox Exp $ */
/* $Id: rdataset.c,v 1.84.186.2.48.3 2011/06/21 20:14:47 each Exp $ */
/*! \file */
@@ -34,6 +34,26 @@
#include <dns/rdataset.h>
#include <dns/compress.h>
static const char *trustnames[] = {
"none",
"pending-additional",
"pending-answer",
"additional",
"glue",
"answer",
"authauthority",
"authanswer",
"secure",
"local" /* aka ultimate */
};
const char *
dns_trust_totext(dns_trust_t trust) {
if (trust >= sizeof(trustnames)/sizeof(*trustnames))
return ("bad");
return (trustnames[trust]);
}
void
dns_rdataset_init(dns_rdataset_t *rdataset) {
@@ -325,7 +345,7 @@ towiresorted(dns_rdataset_t *rdataset, const dns_name_t *owner_name,
count = 1;
result = dns_rdataset_first(rdataset);
INSIST(result == ISC_R_NOMORE);
} else if (rdataset->type == 0) {
} else if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0) {
/*
* This is a negative caching rdataset.
*/
+8 -7
View File
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: resolver.c,v 1.413.14.15 2011/01/27 23:46:37 tbox Exp $ */
/* $Id: resolver.c,v 1.413.14.15.12.1 2011/06/21 20:14:47 each Exp $ */
/*! \file */
@@ -426,6 +426,7 @@ struct dns_resolver {
FCTX_ADDRINFO_TRIED) != 0)
#define NXDOMAIN(r) (((r)->attributes & DNS_RDATASETATTR_NXDOMAIN) != 0)
#define NEGATIVE(r) (((r)->attributes & DNS_RDATASETATTR_NEGATIVE) != 0)
static void destroy(dns_resolver_t *res);
static void empty_bucket(dns_resolver_t *res);
@@ -1050,7 +1051,7 @@ fctx_sendevents(fetchctx_t *fctx, isc_result_t result, int line) {
* Negative results must be indicated in event->result.
*/
if (dns_rdataset_isassociated(event->rdataset) &&
event->rdataset->type == dns_rdatatype_none) {
NEGATIVE(event->rdataset)) {
INSIST(event->result == DNS_R_NCACHENXDOMAIN ||
event->result == DNS_R_NCACHENXRRSET);
}
@@ -4219,7 +4220,7 @@ validated(isc_task_t *task, isc_event_t *event) {
if (result != ISC_R_SUCCESS &&
result != DNS_R_UNCHANGED)
goto noanswer_response;
if (ardataset != NULL && ardataset->type == 0) {
if (ardataset != NULL && NEGATIVE(ardataset)) {
if (NXDOMAIN(ardataset))
eresult = DNS_R_NCACHENXDOMAIN;
else
@@ -4540,7 +4541,7 @@ cache_name(fetchctx_t *fctx, dns_name_t *name, dns_adbaddrinfo_t *addrinfo,
result = ISC_R_SUCCESS;
if (!need_validation &&
ardataset != NULL &&
ardataset->type == 0) {
NEGATIVE(ardataset)) {
/*
* The answer in the cache is
* better than the answer we
@@ -4670,7 +4671,7 @@ cache_name(fetchctx_t *fctx, dns_name_t *name, dns_adbaddrinfo_t *addrinfo,
if (result == DNS_R_UNCHANGED) {
if (ANSWER(rdataset) &&
ardataset != NULL &&
ardataset->type == 0) {
NEGATIVE(ardataset)) {
/*
* The answer in the cache is better
* than the answer we found, and is
@@ -4700,7 +4701,7 @@ cache_name(fetchctx_t *fctx, dns_name_t *name, dns_adbaddrinfo_t *addrinfo,
* Negative results must be indicated in event->result.
*/
if (dns_rdataset_isassociated(event->rdataset) &&
event->rdataset->type == dns_rdatatype_none) {
NEGATIVE(event->rdataset)) {
INSIST(eresult == DNS_R_NCACHENXDOMAIN ||
eresult == DNS_R_NCACHENXRRSET);
}
@@ -4780,7 +4781,7 @@ ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
* care about whether it is DNS_R_NCACHENXDOMAIN or
* DNS_R_NCACHENXRRSET then extract it.
*/
if (ardataset->type == 0) {
if (NEGATIVE(ardataset)) {
/*
* The cache data is a negative cache entry.
*/
+25 -16
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: validator.c,v 1.182.16.14 2010/11/16 01:21:49 marka Exp $ */
/* $Id: validator.c,v 1.182.16.14.10.3 2011/06/21 20:14:47 each Exp $ */
#include <config.h>
@@ -129,6 +129,8 @@
#define SHUTDOWN(v) (((v)->attributes & VALATTR_SHUTDOWN) != 0)
#define CANCELED(v) (((v)->attributes & VALATTR_CANCELED) != 0)
#define NEGATIVE(r) (((r)->attributes & DNS_RDATASETATTR_NEGATIVE) != 0)
static void
destroy(dns_validator_t *val);
@@ -420,7 +422,8 @@ fetch_callback_validator(isc_task_t *task, isc_event_t *event) {
validator_done(val, ISC_R_CANCELED);
} else if (eresult == ISC_R_SUCCESS) {
validator_log(val, ISC_LOG_DEBUG(3),
"keyset with trust %d", rdataset->trust);
"keyset with trust %s",
dns_trust_totext(rdataset->trust));
/*
* Only extract the dst key if the keyset is secure.
*/
@@ -497,7 +500,8 @@ dsfetched(isc_task_t *task, isc_event_t *event) {
validator_done(val, ISC_R_CANCELED);
} else if (eresult == ISC_R_SUCCESS) {
validator_log(val, ISC_LOG_DEBUG(3),
"dsset with trust %d", rdataset->trust);
"dsset with trust %s",
dns_trust_totext(rdataset->trust));
val->dsset = &val->frdataset;
result = validatezonekey(val);
if (result != DNS_R_WAIT)
@@ -652,7 +656,8 @@ keyvalidated(isc_task_t *task, isc_event_t *event) {
validator_done(val, ISC_R_CANCELED);
} else if (eresult == ISC_R_SUCCESS) {
validator_log(val, ISC_LOG_DEBUG(3),
"keyset with trust %d", val->frdataset.trust);
"keyset with trust %s",
dns_trust_totext(val->frdataset.trust));
/*
* Only extract the dst key if the keyset is secure.
*/
@@ -723,15 +728,15 @@ dsvalidated(isc_task_t *task, isc_event_t *event) {
isc_boolean_t have_dsset;
dns_name_t *name;
validator_log(val, ISC_LOG_DEBUG(3),
"%s with trust %d",
"%s with trust %s",
val->frdataset.type == dns_rdatatype_ds ?
"dsset" : "ds non-existance",
val->frdataset.trust);
dns_trust_totext(val->frdataset.trust));
have_dsset = ISC_TF(val->frdataset.type == dns_rdatatype_ds);
name = dns_fixedname_name(&val->fname);
if ((val->attributes & VALATTR_INSECURITY) != 0 &&
val->frdataset.covers == dns_rdatatype_ds &&
val->frdataset.type == 0 &&
NEGATIVE(&val->frdataset) &&
isdelegation(name, &val->frdataset, DNS_R_NCACHENXRRSET)) {
if (val->mustbesecure) {
validator_log(val, ISC_LOG_WARNING,
@@ -1377,8 +1382,8 @@ view_find(dns_validator_t *val, dns_name_t *name, dns_rdatatype_t type) {
INSIST(type == dns_rdatatype_dlv);
if (val->frdataset.trust != dns_trust_secure) {
validator_log(val, ISC_LOG_DEBUG(3),
"covering nsec: trust %u",
val->frdataset.trust);
"covering nsec: trust %s",
dns_trust_totext(val->frdataset.trust));
goto notfound;
}
result = dns_rdataset_first(&val->frdataset);
@@ -1713,8 +1718,8 @@ get_key(dns_validator_t *val, dns_rdata_rrsig_t *siginfo) {
* See if we've got the key used in the signature.
*/
validator_log(val, ISC_LOG_DEBUG(3),
"keyset with trust %d",
val->frdataset.trust);
"keyset with trust %s",
dns_trust_totext(val->frdataset.trust));
result = get_dst_key(val, siginfo, val->keyset);
if (result != ISC_R_SUCCESS) {
/*
@@ -2484,8 +2489,11 @@ validatezonekey(dns_validator_t *val) {
" insecure DS");
return (DNS_R_MUSTBESECURE);
}
markanswer(val, "validatezonekey (2)");
return (ISC_R_SUCCESS);
if (val->view->dlv == NULL || DLVTRIED(val)) {
markanswer(val, "validatezonekey (2)");
return (ISC_R_SUCCESS);
}
return (startfinddlvsep(val, val->event->name));
}
/*
@@ -3223,7 +3231,8 @@ dlvvalidated(isc_task_t *task, isc_event_t *event) {
validator_done(val, ISC_R_CANCELED);
} else if (eresult == ISC_R_SUCCESS) {
validator_log(val, ISC_LOG_DEBUG(3),
"dlvset with trust %d", val->frdataset.trust);
"dlvset with trust %s",
dns_trust_totext(val->frdataset.trust));
dns_rdataset_clone(&val->frdataset, &val->dlv);
val->havedlvsep = ISC_TRUE;
if (dlv_algorithm_supported(val))
@@ -3959,7 +3968,7 @@ validator_start(isc_task_t *task, isc_event_t *event) {
val->attributes |= VALATTR_NEEDNODATA;
result = nsecvalidate(val, ISC_FALSE);
} else if (val->event->rdataset != NULL &&
val->event->rdataset->type == 0)
NEGATIVE(val->event->rdataset))
{
/*
* This is a nonexistence validation.
+1
View File
@@ -652,6 +652,7 @@ dns_tkey_processgssresponse
dns_tkey_processquery
dns_tkeyctx_create
dns_tkeyctx_destroy
dns_trust_totext
dns_tsig_sign
dns_tsig_verify
dns_tsigkey_attach
+24 -23
View File
@@ -1,4 +1,5 @@
./.cvsignore X 1998,1999,2000,2001,2004
./Atffile X 2011
./CHANGES X 2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./COPYRIGHT TXT 1996,1997,1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./EXCLUDED X 2010,2011
@@ -7,9 +8,6 @@
./HISTORY X 2010
./Makefile.in MAKE 1998,1999,2000,2001,2002,2004,2005,2006,2007,2008,2009
./README X 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./RELEASE-NOTES-BIND-9.7.3.html X 2011
./RELEASE-NOTES-BIND-9.7.3.pdf X 2011
./RELEASE-NOTES-BIND-9.7.3.txt X 2011
./acconfig.h C 1999,2000,2001,2002,2003,2004,2005,2007,2008
./aclocal.m4 X 1999,2000,2001
./bin/.cvsignore X 1998,1999,2000,2001
@@ -142,7 +140,7 @@
./bin/named/Makefile.in MAKE 1998,1999,2000,2001,2002,2004,2005,2006,2007,2008,2009,2010
./bin/named/bind.keys.h X 2009,2010,2011
./bin/named/bind9.xsl SGML 2006,2007,2008,2009
./bin/named/bind9.xsl.h X 2007,2008,2009
./bin/named/bind9.xsl.h X 2007,2008,2009,2011
./bin/named/bindkeys.pl PERL 2009,2010
./bin/named/builtin.c C 2001,2002,2003,2004,2005,2007,2009,2010
./bin/named/client.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
@@ -678,30 +676,33 @@
./bin/tests/system/dialup/setup.sh SH 2000,2001,2004,2007
./bin/tests/system/dialup/tests.sh SH 2000,2001,2004,2007
./bin/tests/system/digcomp.pl PERL 2000,2001,2004,2007
./bin/tests/system/dlv/clean.sh SH 2004,2007,2010
./bin/tests/system/dlv/ns1/named.conf CONF-C 2004,2007
./bin/tests/system/dlv/ns1/root.db ZONE 2004,2007
./bin/tests/system/dlv/clean.sh SH 2004,2007,2010,2011
./bin/tests/system/dlv/ns1/named.conf CONF-C 2004,2007,2011
./bin/tests/system/dlv/ns1/root.db.in ZONE 2011
./bin/tests/system/dlv/ns1/rootservers.utld.db ZONE 2004,2007
./bin/tests/system/dlv/ns1/sign.sh SH 2011
./bin/tests/system/dlv/ns2/druz.db.in ZONE 2011
./bin/tests/system/dlv/ns2/hints ZONE 2004,2007
./bin/tests/system/dlv/ns2/named.conf CONF-C 2004,2007
./bin/tests/system/dlv/ns2/named.conf CONF-C 2004,2007,2011
./bin/tests/system/dlv/ns2/sign.sh SH 2011
./bin/tests/system/dlv/ns2/utld.db ZONE 2004,2007
./bin/tests/system/dlv/ns3/child.db.in ZONE 2004,2007,2010
./bin/tests/system/dlv/ns3/dlv.db.in ZONE 2004,2007
./bin/tests/system/dlv/ns3/hints ZONE 2004,2007
./bin/tests/system/dlv/ns3/named.conf CONF-C 2004,2007
./bin/tests/system/dlv/ns3/sign.sh SH 2004,2007,2009,2010
./bin/tests/system/dlv/ns3/named.conf CONF-C 2004,2007,2011
./bin/tests/system/dlv/ns3/sign.sh SH 2004,2007,2009,2010,2011
./bin/tests/system/dlv/ns4/child.db ZONE 2004,2007
./bin/tests/system/dlv/ns4/hints ZONE 2004,2007
./bin/tests/system/dlv/ns4/named.conf CONF-C 2004,2007
./bin/tests/system/dlv/ns5/hints ZONE 2004,2007
./bin/tests/system/dlv/ns5/named.conf CONF-C 2004,2006,2007
./bin/tests/system/dlv/ns5/named.conf CONF-C 2004,2006,2007,2011
./bin/tests/system/dlv/ns5/rndc.conf CONF-C 2004,2007
./bin/tests/system/dlv/ns6/child.db.in ZONE 2010
./bin/tests/system/dlv/ns6/hints ZONE 2010
./bin/tests/system/dlv/ns6/named.conf CONF-C 2010
./bin/tests/system/dlv/ns6/sign.sh SH 2010
./bin/tests/system/dlv/setup.sh SH 2004,2007,2009
./bin/tests/system/dlv/tests.sh SH 2004,2007,2010
./bin/tests/system/dlv/ns6/named.conf CONF-C 2010,2011
./bin/tests/system/dlv/ns6/sign.sh SH 2010,2011
./bin/tests/system/dlv/setup.sh SH 2004,2007,2009,2011
./bin/tests/system/dlv/tests.sh SH 2004,2007,2010,2011
./bin/tests/system/dlz/clean.sh SH 2010
./bin/tests/system/dlz/ns1/dns-root/com/example/dns.d/@/DNAME=10=example.net.= TXT.BRIEF 2010
./bin/tests/system/dlz/ns1/dns-root/com/example/dns.d/@/NS=10=example.com.= TXT.BRIEF 2010
@@ -1938,7 +1939,7 @@
./lib/dns/include/dns/log.h C 1999,2000,2001,2003,2004,2005,2006,2007,2009
./lib/dns/include/dns/lookup.h C 2000,2001,2004,2005,2006,2007,2009
./lib/dns/include/dns/master.h C 1999,2000,2001,2002,2004,2005,2006,2007,2008,2009
./lib/dns/include/dns/masterdump.h C 1999,2000,2001,2002,2004,2005,2006,2007,2008
./lib/dns/include/dns/masterdump.h C 1999,2000,2001,2002,2004,2005,2006,2007,2008,2011
./lib/dns/include/dns/message.h C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009
./lib/dns/include/dns/name.h C 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2009,2010
./lib/dns/include/dns/ncache.h C 1999,2000,2001,2002,2004,2005,2006,2007,2008,2009,2010
@@ -1954,7 +1955,7 @@
./lib/dns/include/dns/rdata.h C 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009
./lib/dns/include/dns/rdataclass.h C 1998,1999,2000,2001,2004,2005,2006,2007
./lib/dns/include/dns/rdatalist.h C 1999,2000,2001,2004,2005,2006,2007,2008
./lib/dns/include/dns/rdataset.h C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/include/dns/rdataset.h C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./lib/dns/include/dns/rdatasetiter.h C 1999,2000,2001,2004,2005,2006,2007
./lib/dns/include/dns/rdataslab.h C 1999,2000,2001,2002,2004,2005,2006,2007,2008
./lib/dns/include/dns/rdatatype.h C 1998,1999,2000,2001,2004,2005,2006,2007,2008
@@ -2000,10 +2001,10 @@
./lib/dns/log.c C 1999,2000,2001,2003,2004,2005,2006,2007,2009
./lib/dns/lookup.c C 2000,2001,2003,2004,2005,2007
./lib/dns/master.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009
./lib/dns/masterdump.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009
./lib/dns/message.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/masterdump.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2011
./lib/dns/message.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./lib/dns/name.c C 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/ncache.c C 1999,2000,2001,2002,2003,2004,2005,2007,2008,2010
./lib/dns/ncache.c C 1999,2000,2001,2002,2003,2004,2005,2007,2008,2010,2011
./lib/dns/nsec.c C 1999,2000,2001,2003,2004,2005,2007,2008,2009
./lib/dns/nsec3.c C 2006,2008,2009,2010
./lib/dns/openssl_link.c C.NAI 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
@@ -2139,7 +2140,7 @@
./lib/dns/rdata/rdatastructsuf.h C 1999,2000,2001,2004,2007
./lib/dns/rdatalist.c C 1999,2000,2001,2003,2004,2005,2007,2008,2010
./lib/dns/rdatalist_p.h C 2000,2001,2004,2005,2007,2008
./lib/dns/rdataset.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/rdataset.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./lib/dns/rdatasetiter.c C 1999,2000,2001,2004,2005,2007
./lib/dns/rdataslab.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/request.c C 2000,2001,2002,2004,2005,2006,2007,2008,2009
@@ -2164,14 +2165,14 @@
./lib/dns/tsec.c C 2009,2010
./lib/dns/tsig.c C 1999,2000,2001,2002,2004,2005,2006,2007,2008,2009,2010
./lib/dns/ttl.c C 1999,2000,2001,2004,2005,2007
./lib/dns/validator.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/validator.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./lib/dns/version.c C 1998,1999,2000,2001,2004,2005,2007
./lib/dns/view.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/win32/DLLMain.c C 2001,2004,2007
./lib/dns/win32/gen.dsp X 2001
./lib/dns/win32/gen.dsw X 2001
./lib/dns/win32/gen.mak X 2001,2006
./lib/dns/win32/libdns.def X 2001,2002,2003,2004,2005,2006,2007,2008,2009,2010
./lib/dns/win32/libdns.def X 2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011
./lib/dns/win32/libdns.dsp X 2001,2002,2003,2004,2005,2006,2007,2008,2009
./lib/dns/win32/libdns.dsw X 2001
./lib/dns/win32/libdns.mak X 2001,2002,2003,2004,2005,2006,2007,2008,2009
+3 -3
View File
@@ -1,4 +1,4 @@
# $Id: version,v 1.51.2.11 2011/01/30 08:01:01 marka Exp $
# $Id: version,v 1.51.2.11.12.3 2011/06/21 20:36:58 each Exp $
#
# This file must follow /bin/sh rules. It is imported directly via
# configure.
@@ -6,5 +6,5 @@
MAJORVER=9
MINORVER=7
PATCHVER=3
RELEASETYPE=
RELEASEVER=
RELEASETYPE=-P
RELEASEVER=3